Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\<File name>.exe.lnk
- %TEMP%\content\3888-3460-<File name>.exe-13-23-43-992.dump
- %TEMP%\content\3888-3460-<File name>.exe-13-23-44-003.dump
- %LOCALAPPDATA%\<File name>.exe
- %LOCALAPPDATA%\<File name>.exe
- 'localhost':1528