Technical Information
- %TEMP%\wzgggiuo.js
- %TEMP%\43712.035343182455.exe
- 'by##t.in':80
- http://fa###xwigs.com/AYLsw1
- http://an#####glutenfree.com/WqoNrY
- http://ta###ciadam.com/NhLUBj
- http://eu###trands.com/EcoSIG
- http://le####rsgalaxy.com/580xkK
- http://de###ome.com/1OStd9
- http://mi###cks.com/byOHev
- http://je##nta.com/dmbj7p
- DNS ASK de#####riaitalia.com
- DNS ASK me###ashion.com
- DNS ASK po###chi.com
- DNS ASK mi###cks.com
- DNS ASK de###ome.com
- DNS ASK ne##rre.com
- DNS ASK 1n###print.com
- DNS ASK le####rsgalaxy.com
- DNS ASK em#.com.sg
- DNS ASK eu###trands.com
- DNS ASK in####jules.co.uk
- DNS ASK ta###ciadam.com
- DNS ASK 80####opsocal.com
- DNS ASK an#####glutenfree.com
- DNS ASK la##ven.com
- DNS ASK fa###xwigs.com
- DNS ASK ow###aby.com
- DNS ASK bo####lewes.co.uk
- DNS ASK je##nta.com
- DNS ASK by##t.in
- '<SYSTEM32>\wscript.exe' %TEMP%\WZgGGiuo.js