Technical Information
- %APPDATA%\microsoft\windows\start menu\programs\startup\bz5mrumpp3y.exe
 
- %WINDIR%\syswow64\cmd.exe
 
- '15#.#01.129.91':443
 
- '%APPDATA%\microsoft\windows\start menu\programs\startup\bz5mrumpp3y.exe' "<Full path to file>"
 
- '%WINDIR%\syswow64\cmd.exe'
 - '<Full path to file>' ' (with hidden window)
 - '%APPDATA%\microsoft\windows\start menu\programs\startup\bz5mrumpp3y.exe' "<Full path to file>"' (with hidden window)
 - '%WINDIR%\syswow64\cmd.exe' ' (with hidden window)