Technical Information
- %APPDATA%\clinkm.data
- %APPDATA%\foreground[ГґГ¦]\<File name>.exe
- %HOMEPATH%\desktop\<File name>.lnk
- %APPDATA%\foreground[ГґГ¦]\cloudx6643.ip
- %APPDATA%\foreground[ГґГ¦]\foreground.exe
- '10#.#6.13.253':511
- '10#.#6.13.235':300
- '10#.46.14.4':300
- '10#.#6.139.122':300
- '10#.#6.14.87':300
- '11#.#90.144.73':3389
- '10#.#6.137.235':300
- '10#.#6.139.238':300
- '11#.#1.174.156':3389
- DNS ASK re##.#sasnet.net
- '%APPDATA%\foreground[ГґГ¦]\<File name>.exe' "<Full path to file>"
- '%APPDATA%\foreground[ГґГ¦]\foreground.exe'