Managed XDR

00db7630a72ed1844c5c5c...e2ef3db75bb74b931.docx (Follina) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
00db7630a72ed1844c5c5c1c999d9ab52f099fafba7ec39e2ef3db75bb74b931.docx
Тип файла
Microsoft OOXML
Размер файла
55.9 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
7ec9eb1955eecda64c99c30bdf5a7cbd19f798cd
SHA256
b974c3eec544d0e429d7d57f5f12b555877130c8ab1bd66df2c59c4a56854e04
MD5
007a29221f9747e60bef68398f8bd99c

Вредоносное ПО

  • Follina

Сигнатуры

Initial Access

T1192 downloader_ms_word: Suspicious link to an external file (Microsoft Word)

Execution

T1203 exploit_CVE_2022_30190: Exploitation of Follina (CVE-2022-30190) Vulnerability
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Other

yara_rules: Static rules
test_check_service: Starts services

Похожие отчёты