Managed XDR

fw_-_ext_-cymulation-c...epayloadmacroaccdb.msg — отчёт о динамическом анализе вредоносного файла

Информация о файле

Имя файла
fw_-_ext_-cymulation-cymulatepayloadmacroaccdb.msg
Тип файла
CDFV2 Microsoft Outlook Message
Размер файла
742.5 KB
Первое обнаружение
Последнее обнаружение

Окружение

w10/x86 en

Хеши

SHA1
7cadaff56c31a3850292b95a11b898179a35f903
SHA256
384e84e048eb0e7aa37d798fa82afdb41541ec4e1b6f948aad8ab9ec2a0210cc
MD5
ca1fecc19fb4f8a282109c3ca0668158

Сигнатуры

Execution

T1203 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Defense Evasion

T1027 office_macros_entropy: The document contains a macro with high entropy (a possible sign of obfuscation)
T1027 office_macros_hex_strings: Lines in hex found in document macro
T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1064 office_macros: The document contains macro
T1064 office_macros_strings: Feature lines found in document macro

Discovery

T1497 evasion_trustrecords: Attempts to detect Sandbox exploring trusted documents
T1083 checks_recent_files: Attempt to check recently opened files through registry

Command and Control

T1071.001 office_exploit_http: The document exhibits suspicious behaviour (performs HTTP requests)
T1071.004 office_exploit_dns: The document exhibits suspicious behaviour (performs DNS requests)
T1071.001 network_http: Performs HTTP requests
T1071.001 winhttp_https: Performs HTTP/HTTPS requests using WinHttp

Other

yara_rules: Static rules
dead_host: Connects to IP addresses that do not respond to requests
test_check_service: Starts services