Managed XDR

fw_-_ext_-cymulation-c...acnaggermacroaccdb.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
fw_-_ext_-cymulation-cymulateuacnaggermacroaccdb.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
936.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
847b8ee760b187bba047d9345001eb79941f0657
SHA256
307baa0a24a1d346fd55ee5e8aa87014f165eac7713db86c7ff6a91674c09fc3
MD5
75d44e95b43f93ca3f2c8e6422c53a7c

Сигнатуры

Execution

T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Defense Evasion

T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1027 office_macros_hex_strings: Lines in hex found in document macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Other

yara_rules: Static rules
test_check_service: Starts services