Managed XDR

00db7630a72ed1844c5c5c...e2ef3db75bb74b931.docx (Follina) — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
00db7630a72ed1844c5c5c1c999d9ab52f099fafba7ec39e2ef3db75bb74b931.docx
Тип файла
Microsoft OOXML
Размер файла
59.7 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
315e110775e214c08441353b97d8734b308fc6c4
SHA256
0112993607e04af2c168db47c3f6e0f2b12a6f65a23836cdea87206485a79b1f
MD5
9d20793394b5640520e1c7396ab466bf

Вредоносное ПО

  • Follina

Сигнатуры

Initial Access

T1192 downloader_ms_word: Suspicious link to an external file (Microsoft Word)

Execution

T1203 exploit_CVE_2022_30190: Exploitation of Follina (CVE-2022-30190) Vulnerability
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)

Defense Evasion

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents

Other

yara_rules: Static rules
test_check_service: Starts services

Похожие отчёты