Technical Information
- '%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe'
- '%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe' (downloaded from the Internet)
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe
- 'rg##st.net':80
- rg##st.net/download/56717000/019ca547058dc28b9d64f7e8d7b13ffaa2724fb6/qqqqqqqqq.exe
- DNS ASK rg##st.net