Managed XDR

data-sent-to-personal-...-34057037-4202276.docx — malware analysis report

File info

Filename
data-sent-to-personal-account-gmail-onedrive-34057037-4202276.docx
File type
Microsoft OOXML
File size
20 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
fbd05a0986ef32c91231c962af1f99330626d149
SHA256
21a81584769fe8961b5535d947fffbc53cee76fbde4905761af9f60fe25aa759
MD5
6e0ab6d1a6d6f719e4abf788e18b67cd

Signatures

Execution

T1204.002 office_strings: Office file contains suspicious strings
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 wininet_https: Performs HTTP/HTTPS requests using WinInet

Other

suricata_alert: Malicious traffic detected
test_check_service: Starts services