Technical Information
- [<HKCU>\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] 'svc host' = '%APPDATA%\server\server.exe'
- %APPDATA%\server\server.exe
- %APPDATA%\user.txt
- http://fr###eoip.net/json/
- http://fr###eoip.net/shutdown
- DNS ASK fr###eoip.net
- DNS ASK gr#####2.viewdns.net