SA - SOC205-231 - Malicious Macro has been executed
Автор: InfoSec_Bret
Загружено: 2025-09-13
Просмотров: 83
Continuing with the Security Analyst Path, we tackle an MEDIUM alert for 'Malicious Macro has been executed' event. Was this actual exploitation or just a false alarm?
EventID: 231
Event Time: Feb, 28, 2024, 08:42 AM
Rule: SOC205 - Malicious Macro has been executed
Level: Security Analyst
Hostname: Jayne
Ip Address: 172.16.17.198
File Name: edit1-invoice.docm
File Path: C:\Users\LetsDefend\Downloads\edit1-invoice.docm
File Hash: 1a819d18c9a9de4f81829c4cd55a17f767443c22f9b30ca953866827e5d96fb0
Trigger Reason: Suspicious file detected on system.
AV/EDR Action: Detected
Items in question:
https://www.virustotal.com/gui/file/1...
NOTES:
https://www.greyhathacker.net/?p=500
messbox[.]exe seems to display a PWNED message when run
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: