Technical Information
- %WINDIR%\syswow64\grpconv.exe
- %ALLUSERSPROFILE%\remcos\logs.dat
- '20#.#7.107.123':8780
- 'ge###ugin.net':80
- http://ge###ugin.net/json.gp
- '20#.#7.107.123':8780
- DNS ASK ge###ugin.net
- '%WINDIR%\syswow64\grpconv.exe' ' (with hidden window)
- '%WINDIR%\syswow64\grpconv.exe'