Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\8823.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- '%TEMP%\8823.tmp' --ping<Full path to file> EC575B202DAD5D07146B163D1E4FB02DED34DA1EA2A87F9172B5902BF5AA6E4FE4C2D39175B6DD3B235D2BA75D21D0C63A65FE25401471281A8690344FF38B92
- '%TEMP%\8823.tmp' --ping<Full path to file> EC575B202DAD5D07146B163D1E4FB02DED34DA1EA2A87F9172B5902BF5AA6E4FE4C2D39175B6DD3B235D2BA75D21D0C63A65FE25401471281A8690344FF38B92' (with hidden window)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<PATH_SAMPLE>.docx"