Техническая информация
- %TEMP%\xbammde.js
- %TEMP%\hmvojzf_91391.exe
- 'hn###tore.com':80
- http://ki##s2.com/sNIWPG
- http://in####moto.com.br/po1mbG
- http://tu####citytour.com/LYmCSw
- http://hi####ket.com.ua/N57uWQ
- http://ex#####ntstorestt.com/LhTnpO
- http://pu###apart.com/xZyH9m
- http://ta###iti.com/kajN3s
- http://si####gems.com.au/fz4uAZ
- DNS ASK ki##s2.com
- DNS ASK in####moto.com.br
- DNS ASK ju####tesano.com
- DNS ASK tu####citytour.com
- DNS ASK hi####ket.com.ua
- DNS ASK gr####murah.com.my
- DNS ASK sh##.##upplysystems.com
- DNS ASK ex#####ntstorestt.com
- DNS ASK pu###apart.com
- DNS ASK ta###iti.com
- DNS ASK sh####mejewelry.com
- DNS ASK si####gems.com.au
- DNS ASK ch####utplanet.com
- DNS ASK cr####ljoias.com.br
- DNS ASK ma###s.com.br
- DNS ASK hn###tore.com
- '<SYSTEM32>\wscript.exe' %TEMP%\xBAMMde.js