Technical Information
- %TEMP%\a3bd.tmp
- from <Full path to file> to <PATH_SAMPLE>.docx
- DNS ASK ne###.##ficeapps.live.com
- DNS ASK fi#####.###tings.services.mozilla.com
- '%TEMP%\a3bd.tmp' --ping<Full path to file> A01DFAF467D8CC2B4BC5623007DD5672A241D5CDD5DFA3C79BB05C784814FCB30790435F3EF3B5D64B901724B73B8A40CF2E3E59A08017DBBFC0AF82A46D8A69
- '%ProgramFiles(x86)%\microsoft office\office16\winword.exe' /n "<PATH_SAMPLE>.docx" /o ""
- '%TEMP%\a3bd.tmp' --ping<Full path to file> A01DFAF467D8CC2B4BC5623007DD5672A241D5CDD5DFA3C79BB05C784814FCB30790435F3EF3B5D64B901724B73B8A40CF2E3E59A08017DBBFC0AF82A46D8A69' (with hidden window)