Technical Information
- %WINDIR%\explorer.exe
- %TEMP%\nsb722.tmp\pluqz8z47dlz2w.dll
- 'ke######infusiontexas.com':80
- 'cl#####ailschristy.com':80
- DNS ASK ke######infusiontexas.com
- DNS ASK cl#####ailschristy.com
- DNS ASK su#####anjapanese.com
- '%WINDIR%\syswow64\cscript.exe'
- '%WINDIR%\syswow64\cmd.exe' del "<Full path to file>"