Technical Information
- [<HKLM>\SYSTEM\ControlSet001\Services\IEHost2Services] 'Start' = '00000002'
- '<SYSTEM32>\svchost.exe' -k IEHost2Services
- %TEMP%\160875_res.tmp
- <SYSTEM32>\IEHost2Services.dll
- from %TEMP%\160875_res.tmp to <SYSTEM32>\IEHost2Services.dll
- 'ci####n.gicp.net':6173
- DNS ASK ci####n.gicp.net