Technical Information
- %TEMP%\469a.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- '15#.#01.1.91':443
- DNS ASK ne###.##ficeapps.live.com
- '%TEMP%\469a.tmp' --ping<Full path to file> 7D8D9AAC165EC0E9D31F5F85C23013BBBE2FF16108CAE9903FCC7CA3F67DE13C12185DEC3C66D61098DD57A3AEBE931D06387165F0F5C928093E42FA0C10745B
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.docx" /o ""
- '%TEMP%\469a.tmp' --ping<Full path to file> 7D8D9AAC165EC0E9D31F5F85C23013BBBE2FF16108CAE9903FCC7CA3F67DE13C12185DEC3C66D61098DD57A3AEBE931D06387165F0F5C928093E42FA0C10745B' (with hidden window)