Execution
T1203 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1559 dde_img: Office document has an INCLUDEPICTURE with external link
T1204.002 office_strings: Office file contains suspicious strings
Command and Control
T1071.001 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behavior (performs DNS requests)
T1071.001 network_http: Performs HTTP requests
Other
suricata_alert: Malicious traffic detected
suspicious_network_port: Performs TCP or UDP request to non-standard port