Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.lnk
- %WINDIR%\tasks\bidaily synchronize task.job
- <SYSTEM32>\tasks\bidaily synchronize task
- %PROGRAMDATA%\{0e11b73b-84f5-5741-0e11-1b73b84fdcee}\<File name>.exe
- %PROGRAMDATA%\{0e11b73b-84f5-5741-0e11-1b73b84fdcee}\<File name>.dat
- DNS ASK sh####-models.com
- DNS ASK po####ve-models.com