Technical Information
- %TEMP%\ixlgtozdsvy.js
- %TEMP%\zqsbktj_67382.exe
- %TEMP%\zqsbktj_70601.exe
- %TEMP%\zqsbktj_21836.exe
- 'hn###tore.com':80
- http://rc###namade.com/do48kR
- http://pa##ra.com/2h06OR
- http://lu###bling.com/UK0NdI
- http://ir##ems.com/Cg6yib
- http://in####astminute.com/3TFsAP
- http://ci#####tinhas.com.br/3I5ySB
- http://el###cadote.com/tTEcWD
- http://is###lstyle.com/gqD9aA
- http://gr####lounge.com/iwFqDz
- http://de#.#queezy.ie/3RfEkY
- http://mu###mart.com/QyZkdj
- http://fo###m-bg.com/g9zV13
- http://rh###obal.com/HiY4EN
- http://hi####ket.com.ua/tsnuaA
- http://ed##kb.ru/g9UReM
- DNS ASK rc###namade.com
- DNS ASK ed##kb.ru
- DNS ASK yo####tionstore.com
- DNS ASK de####hopper.com
- DNS ASK hi####ket.com.ua
- DNS ASK rh###obal.com
- DNS ASK fo###m-bg.com
- DNS ASK li##uce.com
- DNS ASK mu###mart.com
- DNS ASK ca###ecakes.com
- DNS ASK de#.#queezy.ie
- DNS ASK gr####lounge.com
- DNS ASK is###lstyle.com
- DNS ASK gr####murah.com.my
- DNS ASK wl###tore.com
- DNS ASK di#####tbandmerch.com
- DNS ASK el###cadote.com
- DNS ASK ci#####tinhas.com.br
- DNS ASK te###-foni.com
- DNS ASK ex#####onellehair.com
- DNS ASK in####astminute.com
- DNS ASK ir##ems.com
- DNS ASK lu###bling.com
- DNS ASK pa##ra.com
- DNS ASK sa####boutique.com
- DNS ASK hn###tore.com
- '<SYSTEM32>\wscript.exe' %TEMP%\IxlgTOzdsvY.js