Technical Information
- <SYSTEM32>\tasks\microsoft updater
- %TEMP%\jvtmo.dll
- %TEMP%\content\4172-1092-<File name>.exe-20-03-05-777.dump
- %TEMP%\free.exe
- %TEMP%\client-built.exe
- %TEMP%\content\4200-4856-client-built.exe-20-03-22-464.dump
- %APPDATA%\microsoftoffice\officeupdater.exe
- %LOCALAPPDATA%\microsoft\clr_v4.0\usagelogs\client-built.exe.log
- %TEMP%\content\2644-1140-officeupdater.exe-20-03-24-903.dump
- %TEMP%\content\2644-1140-officeupdater.exe-20-03-27-018.dump
- %APPDATA%\microsoftoffice\officeupdater.exe
- DNS ASK ip##pi.com
- DNS ASK fa######56015.portmap.host
- '%TEMP%\free.exe'
- '%TEMP%\client-built.exe'
- '%APPDATA%\microsoftoffice\officeupdater.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "Microsoft Updater" /sc ONLOGON /tr "%APPDATA%\MicrosoftOffice\OfficeUpdater.exe" /rl HIGHEST /f