Execution
T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1559 suspicious_process: Spawns a suspicious process
T1559 dde_img: Office document has an INCLUDEPICTURE with external link
Privilege Escalation
T1134 opens_thread_token: Opens the access token associated with a thread
Defense Evasion
T1134 opens_thread_token: Opens the access token associated with a thread
Credential Access
T1555.003 cookie_files: Accesses cookie files
T1552 cookie_files: Accesses cookie files
Command and Control
T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 network_http: Performs HTTP requests
Other
yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
office_summary: The document contains suspicious metadata
creates_in_programdata: Creates files in the ProgramData directory