Managed XDR

fw_-_ext_-cymulation-c...acnaggermacroaccdb.msg — malware analysis report

File info

Filename
fw_-_ext_-cymulation-cymulateuacnaggermacroaccdb.msg
File type
CDFV2 Microsoft Outlook Message
File size
936.5 KB
First seen
Last seen

Environment

w10/x86 en

Hashes

SHA1
847b8ee760b187bba047d9345001eb79941f0657
SHA256
307baa0a24a1d346fd55ee5e8aa87014f165eac7713db86c7ff6a91674c09fc3
MD5
75d44e95b43f93ca3f2c8e6422c53a7c

Signatures

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Defense Evasion

T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1027 office_macros_hex_strings: Lines in hex found in document macro
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Discovery

T1083 checks_recent_files: Attempt to check recently opened files through registry
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Other

yara_rules: Static rules
test_check_service: Starts services