Execution
T1203 office_exploit_creates_cmd: The document exhibits suspicious behaviour (creates a cmd.exe process)
T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1064 office_macros_suspicious: Document contains suspicious macro
T1106 susp_callbacks: Suspicious usage of some WinAPI with callbacks
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
Defense Evasion
T1027.002 decompress_pefile: Unpacks a PE file into memory
T1027.002 unnamed_memory_regions: Code was executed in unnamed regions
T1140 decompress_pefile: Unpacks a PE file into memory
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1064 office_macros_suspicious: Document contains suspicious macro
T1140 unpacking_utilities: Uses Windows utilities to unpack data
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1134 opens_thread_token: Opens the access token associated with a thread
T1134 opens_process_token: Opens the access token associated with a process
T1064 office_macros: The document contains macro
T1064 office_macros_autoexec: The document contains an auto-start macro
Credential Access
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
Discovery
T1518.001 antiav_detectreg: Attempts to detect installed antiviruses by a certain registry key
T1497.003 antisandbox_sleep: The process attempted to slow down analysis
T1057 process_interest: Enumerates processes
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1497.001 antivm_queries_computername: Retrieves the computer name
T1083 checks_recent_files: Attempt to check recently opened files through registry
Command and Control
T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1032 internet_security_options: Sets Internet connections options that are not secure
T1071 internet_security_options: Sets Internet connections options that are not secure
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet
Exfiltration
T1022 encrypts_pc_info: Collects and encrypts information about the computer (possibly for exfiltration)
Other
yara_rules: Static rules
executes_dropped_exe: Executes dropped exe files
dridex_apis: Dridex banking Trojan detected
creates_in_windows: Creates files in the Windows directory
creates_exe: Creates executable files in the file system
dead_host: Connects to IP addresses that do not respond to requests
create_rpc_bindings: Creates RPC connection
get_policy_info: Retrieves information about a Policy object
suspicious_network_port: Performs TCP or UDP request to non-standard port
test_check_service: Starts services
antisandbox_check_graphics_card: Uses CreateDXGIFactory, potentially to detect graphics card
checktokenmembership: Checks user token with CheckTokenMembership call
open_winlogon_process: Trying to open winlogon process