logo

Triaging MalDocs with Spectra Analyze

ID: b79823b5-0d0d-5837-88d0-89187ef7b55c

STIX ID: report--b79823b5-0d0d-5837-88d0-89187ef7b55c

Feed Name: ReversingLabs Blog

Threat Score
55/100

Date Published: 2025-10-23

Date Updated: 2026-04-29

Author: Ashlee Benge

...
...

This report demonstrates using Spectra Analyze and Spectra Core to triage a malicious Office document (UT.xls) that contains a VBA macro which contacts Dropbox to retrieve a secondary payload and modifies registry settings to bypass macro/security warnings. It covers dynamic sandboxing to extract network indicators (IPs and Dropbox URLs), static analysis of extracted VBA for behavioral strings and registry tampering, construction of advanced searches and YARA-compatible strings for threat hunting, and identification of related samples in a broader campaign.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.