Technical Information
- %HOMEPATH%\start menu\programs\startup\<File name>.lnk
- %ALLUSERSPROFILE%\application data\{0ecdd410-e7f3-0bd7-0ecd-dd410e7f5043}\<File name>.exe
- %ALLUSERSPROFILE%\application data\{0ecdd410-e7f3-0bd7-0ecd-dd410e7f5043}\<File name>.dat
- DNS ASK sh####-models.com
- DNS ASK gu###liban.info