Technical Information
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1400' = '00000003'
- [HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4] '1C00' = '00000000'
- %TEMP%\bbef.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- '%TEMP%\bbef.tmp' --ping<Full path to file> 6BA575B2F2C6C49E9EE93D4AD2C0A9411F0B6467035B7D8FDDBCA238FF5DD441E1652960DCEF54A32749C163951AEA2D15F272AA5012715F92B6FD7357D5193B
- '%TEMP%\bbef.tmp' --ping<Full path to file> 6BA575B2F2C6C49E9EE93D4AD2C0A9411F0B6467035B7D8FDDBCA238FF5DD441E1652960DCEF54A32749C163951AEA2D15F272AA5012715F92B6FD7357D5193B' (with hidden window)
- '%ProgramFiles%\microsoft office\office14\winword.exe' /n "<PATH_SAMPLE>.docx"