The HACKSFASE backdoor is installed as a Windows service and is hard-coded to communicate with a designated command and control server. The address of the command and control server is encrypted and stored at the end of the binary. ref. http://intelreport.mandiant.com/Mandiant_APT1_Report_Appendix.zip p.52