49d9e68dbb6a4bfc5122545b2150adfc3b0ac99f717a1676a5de1e6865c8143b (SHA256)
share.cgissid07Ua3Tpfid07Ua3TpfilenameRFQ0332.xlsopenfolderforcedownloadep.xls
Created at 2018-04-18 14:33:00
Severity | Category | Operation | Classification | |
---|---|---|---|---|
4/5
|
Process | Creates process | - | |
|
||||
|
||||
4/5
|
Device | Monitors keyboard input | Keylogger | |
|
||||
4/5
|
File System | Associated with malicious files | Trojan | |
|
||||
|
||||
4/5
|
Network | Downloads data | Downloader | |
|
||||
|
||||
3/5
|
Network | Performs DNS request | - | |
|
||||
|
||||
3/5
|
Persistence | Installs system startup script or application | - | |
|
||||
3/5
|
Browser | Reads data related to saved browser credentials | - | |
|
||||
3/5
|
Network | Checks external IP address | - | |
|
||||
3/5
|
PE | Executes dropped PE file | - | |
|
||||
2/5
|
Network | Associated with known malicious/suspicious URLs | - | |
|
||||
2/5
|
Network | Connects to HTTP server | - | |
|
||||
|
||||
2/5
|
PE | Drops PE file | Dropper | |
|
||||
2/5
|
VBA Macro | Creates suspicious COM object | - | |
|
||||
1/5
|
Process | Creates system object | - | |
|
||||
1/5
|
VBA Macro | Executes macro on specific worksheet event | - | |
|
||||
|
||||
|