Technical Information
- '<SYSTEM32>\emtmp1.exe'
- '<SYSTEM32>\emtmp1.exe' (downloaded from the Internet)
- <SYSTEM32>\emtmp1.exe
- <SYSTEM32>\eMu1e.tmp
- <SYSTEM32>\emtmp1.exe
- 'fr####ogla.vicp.net':80
- fr####ogla.vicp.net/download/em_setup.exe
- DNS ASK fr####ogla.vicp.net