Техническая информация
- %TEMP%\fygcy.js
- %TEMP%\czkemce_92231.exe
- 'hn###tore.com':80
- http://my###tstore.com/LSGA6M
- http://gr####lounge.com/iwFqDz
- http://th####ding.pictures/EnKLJk
- http://sh###lovers.com/PT5bdR
- http://th####yhorse.com/UK3BvT
- http://go###zon.com/6WcNjA
- http://ci#####tinhas.com.br/3I5ySB
- http://si####gems.com.au/lczTQ6
- DNS ASK sh#######atrizexpress.com.br
- DNS ASK ci#####tinhas.com.br
- DNS ASK go###zon.com
- DNS ASK gr####murah.com.my
- DNS ASK th####yhorse.com
- DNS ASK sh###lovers.com
- DNS ASK th####ding.pictures
- DNS ASK si####gems.com.au
- DNS ASK ho####sire.co.uk
- DNS ASK te########dofgiftsandbargains.co.uk
- DNS ASK sa####boutique.com
- DNS ASK gr####lounge.com
- DNS ASK ho####tphuvinh.com
- DNS ASK lo###rana.com
- DNS ASK my###tstore.com
- DNS ASK st#####ryourhome.co.uk
- DNS ASK hn###tore.com
- '<SYSTEM32>\wscript.exe' %TEMP%\FyGCy.js