Warning message... Link to action
In MITRE's evaluation of EDR solutions, Windows Defender ATP demonstrated industry-leading optics and detection capabilities Read the blog: Insights from the MITRE evaluation
Aliases: No associated aliases
Windows Defender Antivirus detects and removes this threat.
This threat uses an infected Microsoft Office file to download ransomware and other malware onto your PC.
It can arrive on your PC as spam email attachment, usually as a Word file (.doc).
As part of our continued efforts to tackle entire classes of threats, Office 365 client applications now integrate with Antimalware Scan Interface (AMSI), enabling Windows Defender ATP and other security solutions to scan macros and other scripts at runtime to check for malicious behavior. Learn how this integration exposes malicious intent even with heavy obfuscation: Office VBA + AMSI: Parting the veil on malicious macros .