Technical Information
- <SYSTEM32>\tasks\office syncsrv
- %TEMP%\dynu4459qu - copy.exe
- %APPDATA%\office04\msscevr.exe
- %TEMP%\dynu4459qu - copy.exe
- %APPDATA%\office04\msscevr.exe
- DNS ASK ip##pi.com
- DNS ASK fr###eoip.net
- DNS ASK ap#.#pify.org
- '%TEMP%\dynu4459qu - copy.exe'
- '%APPDATA%\office04\msscevr.exe'
- '<SYSTEM32>\schtasks.exe' /create /tn "Office SyncSrv" /sc ONLOGON /tr "%TEMP%\dynu4459qu - Copy.exe" /rl HIGHEST /f
- '<SYSTEM32>\schtasks.exe' /create /tn "Office SyncSrv" /sc ONLOGON /tr "%APPDATA%\Office04\msscevr.exe" /rl HIGHEST /f