Technical Information
- %TEMP%\de2b.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- DNS ASK ne###.##ficeapps.live.com
- '%TEMP%\de2b.tmp' --ping<Full path to file> BE381444CFDE525D344808D2360224DD0CF7A2B40A6DE05AEEAC83DEBC77C8A0A4A4CED5AB89091AA95139E0C2D94C98739C222A2543CBE7156C59A3BBBF6956
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.docx" /o ""
- '%TEMP%\de2b.tmp' --ping<Full path to file> BE381444CFDE525D344808D2360224DD0CF7A2B40A6DE05AEEAC83DEBC77C8A0A4A4CED5AB89091AA95139E0C2D94C98739C222A2543CBE7156C59A3BBBF6956' (with hidden window)