Technical Information
- %TEMP%\twnczako.js
- %TEMP%\yldapgp_98489.exe
- %TEMP%\yldapgp_2847.exe
- http://am##sur.com/sJIEQB
- http://ha##mee.com/hIPTXx
- http://ma#####iproperties.com/pQIJGB
- http://pv###jekt.pl/oLlqvX
- http://ad####schubert.pl/7s56K8
- http://10###nsult.com/zZVPJj
- http://pu####afacile.it/JvZ9cX
- http://kv####vaya-lampa.ru/fC9qZW
- http://pg####unitycab.com/FAlx1b
- http://ri####ncoperu.org/B3AlqT
- http://me####esign.info/o12QeD
- DNS ASK ba###ashion.ru
- DNS ASK ri####ncoperu.org
- DNS ASK ro##mind.pl
- DNS ASK pg####unitycab.com
- DNS ASK sa###iumspb.ru
- DNS ASK kv####vaya-lampa.ru
- DNS ASK pu####afacile.it
- DNS ASK 10###nsult.com
- DNS ASK ad####schubert.pl
- DNS ASK pv###jekt.pl
- DNS ASK la###umano.cl
- DNS ASK be###basol.com
- DNS ASK ak##rd.com
- DNS ASK mi#######press-randburg.co.za
- DNS ASK bi#####prservices.com
- DNS ASK ma#####iproperties.com
- DNS ASK ha##mee.com
- DNS ASK am##sur.com
- DNS ASK nw###izel.ru
- DNS ASK me####esign.info
- '<SYSTEM32>\wscript.exe' %TEMP%\twNCZAkO.js