Technical Information
- '%TEMP%\qk1817gp\nlahrtln.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe
- %TEMP%\ieysoqz9.zip
- %TEMP%\qk1817gp\qasxz.exe
- %TEMP%\qk1817gp\nlahrtln.exe
- %TEMP%\qk1817gp\qasxz.exe
- '19#.#5.98.29':80
- http://19#.#5.98.29/host2/QASXZ.zip
- '%WINDIR%\microsoft.net\framework\v4.0.30319\regasm.exe'