Technical Information
- '%TEMP%\d70KLrQfgdEMhtVoyEiV7.exe'
- '%TEMP%\d70KLrQfgdEMhtVoyEiV7.exe' (downloaded from the Internet)
- %TEMP%\d70KLrQfgdEMhtVoyEiV7.exe
- 'tr.##host.net':80
- 'wp#d':80
- tr.##host.net/download/58481597/728896ceb9f5e323c96f9b7f730ab7d053c88469/Crypted.exe
- wp#d/wpad.dat
- DNS ASK tr.##host.net
- DNS ASK wp#d