Managed XDR

maintenance_schedule_overview.docx — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
maintenance_schedule_overview.docx
Тип файла
Microsoft OOXML
Размер файла
32.3 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x64 en

Хеши

SHA1
c32997316ce047df023c140cb52e248c176772e2
SHA256
cfec2dad0bf0ff264fa11f710890f1981d8a0ab0e62bc77be42959c338d60a16
MD5
c4482ae36f9a3aefe1fd8d6f163b2ffa

Сигнатуры

Execution

T1203 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1559 dde_img: Office document has an INCLUDEPICTURE with external link
T1204.002 office_strings: Office file contains suspicious strings

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behavior (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behavior (performs DNS requests)
T1071.001 network_http: Performs HTTP requests

Other

suricata_alert: Malicious traffic detected
suspicious_network_port: Performs TCP or UDP request to non-standard port