Technical Information
- %TEMP%\2b08.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- DNS ASK ne###.##ficeapps.live.com
- '%TEMP%\2b08.tmp' --ping<Full path to file> 27D50C9B50CB319545C6628AB07731C46C3E2FE445C41FB8621A941B449D657327EC7E2E31A5EC2006D91CC910CFBFE74693D098FB7A26C337F3B958D3C3AA87
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.docx" /o ""
- '%TEMP%\2b08.tmp' --ping<Full path to file> 27D50C9B50CB319545C6628AB07731C46C3E2FE445C41FB8621A941B449D657327EC7E2E31A5EC2006D91CC910CFBFE74693D098FB7A26C337F3B958D3C3AA87' (with hidden window)