Technical Information
- [HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] '<File name>' = '%APPDATA%\<File name>.exe'
- %LOCALAPPDATA%\microsoft\clr_v4.0_32\usagelogs\<File name>.exe.log
- %APPDATA%\<File name>.exe
- %TEMP%\e96fa520ae37cd03a3d0d4b87f649496\chromium_cookies_yqwlugus_2026-03-24_18.58.39.json
- %TEMP%\e96fa520ae37cd03a3d0d4b87f649496\gecko_cookies_yqwlugus_2026-03-24_18.58.42.json
- %TEMP%\e96fa520ae37cd03a3d0d4b87f649496\chromium_cookies_yqwlugus_2026-03-24_18.58.39.json
- %TEMP%\e96fa520ae37cd03a3d0d4b87f649496\gecko_cookies_yqwlugus_2026-03-24_18.58.42.json
- DNS ASK ap#.##legram.org