Technical Information
- %LOCALAPPDATA%\google\chrome\user data\default\web data
- %LOCALAPPDATA%\google\chrome\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\login data
- %LOCALAPPDATA%\microsoft\edge\user data\default\web data
- %TEMP%\overplus.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\overplus.exe.log
- 'ip##pi.com':80
- '95.##7.38.47':5460
- http://ip##pi.com/json/
- '95.##7.38.47':5460
- DNS ASK ip##pi.com
- '%TEMP%\overplus.exe'