Technical Information
- %WINDIR%\syswow64\svchost.exe
- 'ic###azip.com':80
- '19#.#49.90.166':12228
- '24.##8.217.188':443
- '20#.#17.68.78':443
- '20#.#29.197.50':443
- http://ic###azip.com/
- '34.##0.144.191':443
- '34.##9.100.209':443
- '34.##7.121.53':443
- DNS ASK ic###azip.com
- '%WINDIR%\syswow64\svchost.exe'