logo

Microsoft Word and Sandboxes

ID: 2af1e79d-ee00-5a79-9cb6-965f0f6eccd4

STIX ID: report--2af1e79d-ee00-5a79-9cb6-965f0f6eccd4

Feed Name: Blaze's Security Blog

Threat Score
30/100

Date Published: 2024-08-14

Date Updated: 2026-04-19

Author: Bart

...
...

This brief post describes two Microsoft Word-related tactics an attacker could use to increase stealth: (1) reading the Office UserName from HKCU\Software\Microsoft\Office\Common\UserInfo for reconnaissance that may not trigger sandbox detection, and (2) renaming malicious documents to .asd/.wbk autosave extensions to evade sandboxes and detection; the write-up highlights these as potential evasion techniques but provides no evidence of active exploitation or a specific campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.