Technical Information
- <SYSTEM32>\cscript.exe
- %ALLUSERSPROFILE%\xis\easll.emi
- %TEMP%\oca.hfe
- 'be###eslrrm.pw':80
- 'pz##mndy.ru':80
- 'dp###lmnw.pw':80
- 'xo##d.in':80
- 'dx##w.pw':80
- 'hg##ssx.ru':80
- 'nf###mroe.com':80
- 'hl##o.ru':80
- 'nj###ooj.com':80
- 'cn###ueulfz.in':80
- 'yl###qdbzw.in':80
- 'bg###qhlk.com':80
- 'fm##wf.com':80
- 'as##kat.pw':80
- 'eb##vtqu.pw':80
- 'bd##b.com':80
- 'rq##id.ru':80
- 'vw###sezloy.in':80
- 'sn##yiv.com':80
- DNS ASK microsoft.com
- DNS ASK pz##mndy.ru
- DNS ASK dp###lmnw.pw
- DNS ASK xo##d.in
- DNS ASK dx##w.pw
- DNS ASK hg##ssx.ru
- DNS ASK nf###mroe.com
- DNS ASK hl##o.ru
- DNS ASK cn###ueulfz.in
- DNS ASK vw###sezloy.in
- DNS ASK yl###qdbzw.in
- DNS ASK bg###qhlk.com
- DNS ASK fm##wf.com
- DNS ASK as##kat.pw
- DNS ASK eb##vtqu.pw
- DNS ASK bd##b.com
- DNS ASK rq##id.ru
- DNS ASK be###eslrrm.pw
- DNS ASK nj###ooj.com
- DNS ASK sn##yiv.com
- '<SYSTEM32>\rundll32.exe' -rr nqg.dll