Technical Information
- '%TEMP%\jnowlrxs.exe' (downloaded from the Internet)
- '%TEMP%\bubejc.exe' (downloaded from the Internet)
- '%TEMP%\kjaabhjt.exe' (downloaded from the Internet)
- '%TEMP%\fbaamp.exe' (downloaded from the Internet)
- '%TEMP%\-1998166001' (downloaded from the Internet)
- '%TEMP%\bbrx.exe' (downloaded from the Internet)
- '%TEMP%\tgxp.exe' (downloaded from the Internet)
- '%TEMP%\kcxow.exe' (downloaded from the Internet)
- '%TEMP%\lfpowf.exe' (downloaded from the Internet)
- '%TEMP%\mtaougq.exe' (downloaded from the Internet)
- '%TEMP%\getnwq.exe' (downloaded from the Internet)
- '%TEMP%\hrtcox.exe' (downloaded from the Internet)
- '%TEMP%\bbrx.exe'
- '%TEMP%\jnowlrxs.exe'
- '%TEMP%\bubejc.exe'
- '<SYSTEM32>\cmd.exe' /c del <Full path to file> > nul
- '%TEMP%\fbaamp.exe'
- '%TEMP%\-1998166001'
- '%TEMP%\kjaabhjt.exe'
- '%TEMP%\tgxp.exe'
- '%TEMP%\kcxow.exe'
- '%TEMP%\lfpowf.exe'
- '%TEMP%\mtaougq.exe'
- '%TEMP%\getnwq.exe'
- '%TEMP%\hrtcox.exe'
- %TEMP%\jnowlrxs.exe
- %TEMP%\bubejc.exe
- %TEMP%\kjaabhjt.exe
- %TEMP%\fbaamp.exe
- %TEMP%\-1998166001
- %TEMP%\bbrx.exe
- %TEMP%\tgxp.exe
- %TEMP%\kcxow.exe
- %TEMP%\lfpowf.exe
- %TEMP%\mtaougq.exe
- %TEMP%\getnwq.exe
- %TEMP%\hrtcox.exe
- 'ab####gnostic.com':80
- http://ab####gnostic.com/utaigom/mdyfelge.php?ad########
- http://ab####gnostic.com/utaigom/txfdyselte.php?ad########
- http://ab####gnostic.com/utaigom/arzuoz.php?ad########
- http://ab####gnostic.com/utaigom/vqkszys.php?ad#################################################
- http://ab####gnostic.com/utaigom/hyxrmxs.php?ad########
- http://ab####gnostic.com/utaigom/dubwucnvg.php?ad########
- http://ab####gnostic.com/utaigom/lcjepkiq.php?ad########
- http://ab####gnostic.com/utaigom/bfzhfdywe.php?ad########
- http://ab####gnostic.com/utaigom/zqksqlje.php?ad########
- http://ab####gnostic.com/utaigom/vzgomuf.php?ad########
- http://ab####gnostic.com/utaigom/ysautnmg.php?ad########
- http://ab####gnostic.com/utaigom/mqlselg.php?ad########
- http://ab####gnostic.com/utaigom/ycpxe.php?ad########
- DNS ASK ab####gnostic.com