Техническая информация
- %TEMP%\lldyprobggzdbo.js
- %TEMP%\lagfhcf_56314.exe
- %TEMP%\lagfhcf_77983.exe
- http://be###ight.org/IDKEeX
- http://ba###xico.com/POltGd
- http://bi###inrus.ru/IzAtbH
- http://ba####thingz.com/FBsQtK
- http://bm##inc.com/4Fv7sK
- http://bo##var.ru/w782j3
- http://as####en.systems/lpQk6P
- http://bi#####inovasyon.org.tr/M4W7Hi
- http://au#####ictherapy.com/GpsCve
- http://ba####sgarden.com/FXPosh
- http://ar####alurji.com/KmvUJ5
- http://ba###ehype.com/plzg3U
- http://bi###ebel.net/KyFfgv
- DNS ASK ba##aal.com
- DNS ASK ar#######ubmissionwebsites.com
- DNS ASK bi####pic.com.tr
- DNS ASK ar####alurji.com
- DNS ASK ba####sgarden.com
- DNS ASK au#####ictherapy.com
- DNS ASK bi#####inovasyon.org.tr
- DNS ASK as####en.systems
- DNS ASK bo##var.ru
- DNS ASK bm##inc.com
- DNS ASK ba####thingz.com
- DNS ASK bi###inrus.ru
- DNS ASK be###y4you.cz
- DNS ASK ba####tsmarried.com
- DNS ASK ba###xico.com
- DNS ASK be###ight.org
- DNS ASK ba###ehype.com
- DNS ASK bi###ebel.net
- '<SYSTEM32>\wscript.exe' %TEMP%\lLDyProBGgZdBo.js