Managed XDR

maintenance_schedule_overview.docx — malware analysis report

File info

Filename
maintenance_schedule_overview.docx
File type
Microsoft OOXML
File size
32.3 KB
First seen
Last seen

Environment

w10/x64 en

Hashes

SHA1
c32997316ce047df023c140cb52e248c176772e2
SHA256
cfec2dad0bf0ff264fa11f710890f1981d8a0ab0e62bc77be42959c338d60a16
MD5
c4482ae36f9a3aefe1fd8d6f163b2ffa

Signatures

Execution

T1203 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1559 dde_img: Office document has an INCLUDEPICTURE with external link
T1204.002 office_strings: Office file contains suspicious strings

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behavior (performs DNS requests)
T1071.001 network_http: Performs HTTP requests

Other

suricata_alert: Malicious traffic detected
suspicious_network_port: Performs TCP or UDP request to non-standard port