Техническая информация
- %TEMP%\lxfkhbr.js
- %TEMP%\fmrrdcv_68112.exe
- %TEMP%\fmrrdcv_13522.exe
- http://ca###rstea.com/1G3mEb
- http://dr###nex.com/w9IjYE
- http://fa###eal.com/8BW1Mx
- http://op##6.ru/q5p7uL
- http://av###ix.com.br/mgw1Z9
- http://as###nyc.com/ZLyoO2
- http://le###alog.com/oN24SU
- http://po####irect.net.au/XMxmTv
- http://we###mpo.com.br/mGX80k
- http://ra####yknickers.com/Ftko5D
- http://wb####online.com/lKUYSO
- DNS ASK ca###rstea.com
- DNS ASK dr###nex.com
- DNS ASK le######cyandsupply.com.sg
- DNS ASK fa###eal.com
- DNS ASK op##6.ru
- DNS ASK av###ix.com.br
- DNS ASK 7i#.com.br
- DNS ASK xi##.com.sg
- DNS ASK as###nyc.com
- DNS ASK ba##aaz.com
- DNS ASK le###alog.com
- DNS ASK po####irect.net.au
- DNS ASK we###mpo.com.br
- DNS ASK ra####yknickers.com
- DNS ASK wb####online.com
- '<SYSTEM32>\wscript.exe' %TEMP%\LxFKHBR.js