Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.lnk
- %WINDIR%\tasks\bidaily synchronize task.job
- <SYSTEM32>\tasks\bidaily synchronize task
- %ALLUSERSPROFILE%\{bbef1d1e-261b-fc4c-bbef-f1d1e2617478}\<File name>.exe
- %ALLUSERSPROFILE%\{bbef1d1e-261b-fc4c-bbef-f1d1e2617478}\<File name>.dat
- %ALLUSERSPROFILE%\microsoft\crypto\rsa\s-1-5-18\d42cc0c3858a58db2db37658219e6400_0cb67e2f-dc95-45ca-8fb8-69bde8e3f814
- DNS ASK le####users.info
- DNS ASK le###-user.com