Technical Information
- %TEMP%\udouesfkzhm.js
- %TEMP%\xrmlrst_56259.exe
- %TEMP%\xrmlrst_62882.exe
- http://ma#####iproperties.com/pQIJGB
- http://pr#####toglass.co.nz/wMcW5Z
- http://c-##r.at/QSa8sI
- http://an####vazquez.net/1UaAWY
- http://ha##mee.com/hIPTXx
- http://ki##off.ru/WNwvki
- http://kt###akis.com/UHqig6
- http://kt###akis.com/?la#####
- http://10###nsult.com/zZVPJj
- http://pv###jekt.pl/oLlqvX
- http://no#####likejones.com/hati3x
- http://mo##.org.mk/oiNWQ0
- DNS ASK ro##mind.pl
- DNS ASK nw###izel.ru
- DNS ASK no#####likejones.com
- DNS ASK bi#####prservices.com
- DNS ASK pv###jekt.pl
- DNS ASK 10###nsult.com
- DNS ASK kt###akis.com
- DNS ASK ki##off.ru
- DNS ASK mo##.org.mk
- DNS ASK ha##mee.com
- DNS ASK c-##r.at
- DNS ASK sa###iumspb.ru
- DNS ASK ca##le78.it
- DNS ASK pr#####toglass.co.nz
- DNS ASK am####-concerts.de
- DNS ASK al###zatrio.com
- DNS ASK ma#####iproperties.com
- DNS ASK an####vazquez.net
- DNS ASK ba###ashion.ru
- '<SYSTEM32>\wscript.exe' %TEMP%\UDOuEsfkzhm.js