Technical Information
- %TEMP%\6gqp0mwlww
- %TEMP%\6gqp0mwlww.dll
- '18#.#27.249.203':80
- '13#.#01.191.196':80
- http://www.ca#####aservices.com/ryhfvuf
- http://ih##.org/txb1n2bm
- http://an######nelli.interfree.it/rfer0z1
- http://18#.#27.249.203/data/info.php
- DNS ASK ca#####aservices.com
- DNS ASK ih##.org
- DNS ASK an######nelli.interfree.it
- '%WINDIR%\syswow64\rundll32.exe' %TEMP%\6GQP0M~1.DLL,qwerty 323