Managed XDR

c-users-user-desktop-document.doc-copy — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
c-users-user-desktop-document.doc-copy
Тип файла
Composite Document File V2 Document, Little Endian, Os: Windows, Version 10.0, Code page: -535, Title: 20231124174046_(), Author: Joseph, Template: Normal, Last Saved By: george, Revision Number: 5, Name of Creating Application: Microsoft Office Word, Total Editing Time: Mon Feb 16 03:32:00 9767, Create Time/Date: Fri Nov 24 17:41:00 2023, Last Saved Time/Date: Fri Jan 10 06:23:00 2025, Number of Pages: 3, Number of Words: 227, Number of Characters: 1299, Security: 0
Размер файла
220 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
47d112960c398afdc389e89220e6b494f95a989c
SHA256
c8950ac21502c3b637bbb9e941aac3d4d8a690788d825120af1d062f6d8eaea6
MD5
76c4525dba33a11d8c7a911a1399d9af

Сигнатуры

Execution

T1203 exploit_CVE_2017_11882: Exploits CVE-2017-11882 vulnerability
T1204.002 office_vb_load: Microsoft Office is loading VB DLL files (macros usage indicator)
T1204.002 office_com_load: Microsoft Office loads COM DLL files (indicator of COM usage in macros)
T1064 office_macros: The document contains macro

Defense Evasion

T1064 office_macros: The document contains macro

Discovery

T1518 locates_browser: Attempts to identify where browsers are installed

Other

dead_host: Connects to IP addresses that do not respond to requests
process_crashed: One of the processes has failed
unexpected_exception: Unexpected exception
creates_suspended_process: Creates suspended process
break_limit_exceeded: Warning: function calls limit has been exceeded
message_box: Displays a message
test_check_service: Starts services