Technical Information
- %TEMP%\b.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- DNS ASK ne###.##ficeapps.live.com
- DNS ASK fi#####.###tings.services.mozilla.com
- '%TEMP%\b.tmp' --ping<Full path to file> 86D259CEAF9364A4C6BA1B2BAC4A408AAC30A32E677255FD9CC57AEBBE5259FDDC8A584EA86258FAAF48C8BDD741032F3925A884998070A19646BB25C1C32568
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.docx" /o ""
- '%TEMP%\b.tmp' --ping<Full path to file> 86D259CEAF9364A4C6BA1B2BAC4A408AAC30A32E677255FD9CC57AEBBE5259FDDC8A584EA86258FAAF48C8BDD741032F3925A884998070A19646BB25C1C32568' (with hidden window)