Technical Information
- '%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe'
- '%APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe' (downloaded from the Internet)
- %APPDATA%\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\svghost.exe
- 'rg##st.net':80
- rg##st.net/download/56714757/5085af876cd594fa60a79b2a148207505a89035c/Server.exe
- DNS ASK rg##st.net