Hi Stroto
-You didn't made any transactions you said last month, but did you log in to MEW with your json file (or any other means)?
Yes, I've used JSON for login in December. On real MEW site.
I just read 0x5e4 in transaction details. As sm.contract which do all this process.
And yes my WiC was transferred to 0x4f - which is end point of the theft.
it is just that 0x5e4 shows ALL wic transactions legit and nonlegit. The focus should lay on the first receiving address 0x4f.
About fishing, etc.
I never do anything what described as fishing. For last ten years at least. Always check where and what I'm doing.
So, now I change almost everything: wallets, passwords, methods of authentication, e-mail's for recovery, etc.
It was much more painful than just 25K of WiC's

That is the most annoying part, but before you change all just ran your system on malware etc. but I assume you already did that.