Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svchost' = '%HOMEPATH%\svchost.exe'
- %WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe
- %HOMEPATH%\svchost.exe
- '54.##.36.116':49746
- '79.##4.225.92':2703
- 'ra#####1.duckdns.org':2703
- DNS ASK ra#####1.duckdns.org
- '%WINDIR%\microsoft.net\framework\v4.0.30319\vbc.exe'