Техническая информация
- %TEMP%\iwbdkeujh.js
- %TEMP%\azjgjta_44694.exe
- %TEMP%\azjgjta_6744.exe
- http://fl###gcarts.com/l17p36
- http://my###tstore.com/LSGA6M
- http://ph##ci.in/7SC0vA
- http://hi####ket.com.ua/tsnuaA
- http://ma####obilya.com/1d9qpc
- http://ev##ees.com/pEFWns
- http://ci#####tinhas.com.br/3I5ySB
- http://ea####tshop.com.br/fkboKu
- http://wh#######.undercovermama.com/zJm4Cd
- http://ro##tte.ro/aDOLTG
- http://me###tcanta.com/4VK1pS
- http://gr####lounge.com/iwFqDz
- http://ex#####ntstorestt.com/Ivszwj
- http://pu###apart.com/YCDUH9
- DNS ASK fl###gcarts.com
- DNS ASK ex#####ntstorestt.com
- DNS ASK gr####lounge.com
- DNS ASK me###tcanta.com
- DNS ASK ro##tte.ro
- DNS ASK wh#######.undercovermama.com
- DNS ASK ea####tshop.com.br
- DNS ASK ya##lom.ca
- DNS ASK ci#####tinhas.com.br
- DNS ASK ev##ees.com
- DNS ASK re######vewebtemplate.com
- DNS ASK cr####ljoias.com.br
- DNS ASK ho####tphuvinh.com
- DNS ASK ma####obilya.com
- DNS ASK hi####ket.com.ua
- DNS ASK ph##ci.in
- DNS ASK re#####rsinsandiego.com
- DNS ASK my###tstore.com
- DNS ASK li##uce.com
- DNS ASK pu###apart.com
- '<SYSTEM32>\wscript.exe' %TEMP%\iWBDKEUjh.js