Triaging MalDocs with Spectra Analyze
ID: b79823b5-0d0d-5837-88d0-89187ef7b55c
STIX ID: report--b79823b5-0d0d-5837-88d0-89187ef7b55c
Feed Name: ReversingLabs Blog
This report demonstrates using Spectra Analyze and Spectra Core to triage a malicious Office document (UT.xls) that contains a VBA macro which contacts Dropbox to retrieve a secondary payload and modifies registry settings to bypass macro/security warnings. It covers dynamic sandboxing to extract network indicators (IPs and Dropbox URLs), static analysis of extracted VBA for behavioral strings and registry tampering, construction of advanced searches and YARA-compatible strings for threat hunting, and identification of related samples in a broader campaign.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
