Technical Information
- %TEMP%\cjhojmplmopd.js
- %TEMP%\xnkvxtx_87539.exe
- %TEMP%\xnkvxtx_72886.exe
- 'bl##.#izmohelp.com':80
- http://au####gunsammo.com/KnCOrh
- http://av##roup.su/KLrgZY
- http://ba####thingz.com/FBsQtK
- http://as####en.systems/lpQk6P
- http://ba###xico.com/POltGd
- http://be###yworld.hu/BAj60H
- http://az##s.com/BCxfzy
- http://au#####ictherapy.com/GpsCve
- DNS ASK ax###overs.com
- DNS ASK az##s.com
- DNS ASK be###yworld.hu
- DNS ASK as###urid.net
- DNS ASK ay####bimbenim.com
- DNS ASK ba###xico.com
- DNS ASK at###tic-co.com
- DNS ASK au#####ictherapy.com
- DNS ASK as####en.systems
- DNS ASK av##roup.su
- DNS ASK bl##.#obrystolik.pl
- DNS ASK av###.com.tr
- DNS ASK bi####pic.com.tr
- DNS ASK au###agic.co.at
- DNS ASK au####gunsammo.com
- DNS ASK ba####thingz.com
- DNS ASK bl##.#izmohelp.com
- '<SYSTEM32>\wscript.exe' %TEMP%\cJHOjMplMopD.js