Technical Information
- %TEMP%\twnczako.js
- %TEMP%\yldapgp_62930.exe
- %TEMP%\yldapgp_51125.exe
- http://ha##mee.com/hIPTXx
- http://no##sys.com/EwX0sO
- http://li##roup.ru/vV9c7l
- http://kv####vaya-lampa.ru/fC9qZW
- http://10###nsult.com/zZVPJj
- http://je###mpiotr.pl/IiJlGp
- http://ro###arita.com/5NmH3b
- http://le######erryconsulting.com/gXTND7
- http://fm##30.us/BznLrm
- DNS ASK al###zatrio.com
- DNS ASK be##v24.ru
- DNS ASK mi#######press-randburg.co.za
- DNS ASK le######erryconsulting.com
- DNS ASK bi#####prservices.com
- DNS ASK la###umano.cl
- DNS ASK ro###arita.com
- DNS ASK je###mpiotr.pl
- DNS ASK ak##rd.com
- DNS ASK 10###nsult.com
- DNS ASK as####station.com
- DNS ASK am####-concerts.de
- DNS ASK kv####vaya-lampa.ru
- DNS ASK re#####.motociclismo.es
- DNS ASK li##roup.ru
- DNS ASK no##sys.com
- DNS ASK ha##mee.com
- DNS ASK af###ityee.com
- DNS ASK fm##30.us
- '<SYSTEM32>\wscript.exe' %TEMP%\twNCZAkO.js