Source: Chapter 4 Test 4A--2013-2014.doc |
Avira: detected |
Source: C:\Users\user\AppData\Local\Temp\Word\Chapter 4 Test 4A--2013-2014.doc |
Avira: detection malicious, Label: EXP/CVE-2018-0798.Gen |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160885555/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160885643/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160890263/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160890468/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160890548/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160890606/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1160890641/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1286867940/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc |
Stream path 'ObjectPool/_1286868111/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160885555/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160885643/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160890263/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160890468/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160890548/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160890606/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1160890641/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1286867940/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
Stream path 'ObjectPool/_1286868111/\x1CompObj' : ...................F....Microsoft Equation 3.0.... |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File created: C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{AD083452-12AD-436F-8C6B-DC3A21245609}.tmp |
Jump to behavior |
Source: Chapter 4 Test 4A--2013-2014.doc |
OLE indicator, ObjectPool: true |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
OLE indicator, ObjectPool: true |
Source: classification engine |
Classification label: mal56.winDOC@1/5@0/0 |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File created: C:\Users\user\AppData\Local\Temp\CVR6A65.tmp |
Jump to behavior |
Source: Chapter 4 Test 4A--2013-2014.doc |
OLE indicator, Word Document stream: true |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
OLE indicator, Word Document stream: true |
Source: Chapter 4 Test 4A--2013-2014.doc |
OLE document summary: title field not present or empty |
Source: Chapter 4 Test 4A--2013-2014.doc |
OLE document summary: author field not present or empty |
Source: Chapter 4 Test 4A--2013-2014.doc |
OLE document summary: edited time not present or 0 |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
OLE document summary: title field not present or empty |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
OLE document summary: author field not present or empty |
Source: Chapter 4 Test 4A--2013-2014.doc.0.dr |
OLE document summary: edited time not present or 0 |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File read: C:\Users\desktop.ini |
Jump to behavior |
Source: Window Recorder |
Window detected: More than 3 window changes detected |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Key opened: HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
File opened: C:\Windows\WinSxS\amd64_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.4940_none_08e4299fa83d7e3c\MSVCR90.dll |
Jump to behavior |
Source: Chapter 4 Test 4A--2013-2014.doc |
Initial sample: OLE indicators vbamacros = False |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |
Source: C:\Program Files\Microsoft Office\Office14\WINWORD.EXE |
Process information set: NOOPENFILEERRORBOX |
Jump to behavior |