Skip to main content
Skip to main content
22 entries found. Displaying page 1 of 2.
Updated on Oct 05, 2016
Alert level: severe
Updated on Jun 11, 2019
Alert level: severe
Updated on Sep 07, 2023
Alert level: severe
Updated on Jan 15, 2016

This threat is associated with an activity group Microsoft tracks as Storm-0201. The following trojan arrives through a malicious macro-enabled Microsoft Word document contained in a ZIP file. The ZIP file is usually a malicious archive file containing large file sizes that can cause programs to crash.

Threat actors use zip bombs specifically to evade cloud-delivered antivirus features, by convincing users to locally download the malicious files to avoid detection by Microsoft’s recent macros disablement. 

Alert level: severe
Updated on Dec 19, 2017
Alert level: severe
Updated on Jun 07, 2019
Alert level: severe
Updated on May 22, 2017
Alert level: severe
Updated on May 27, 2016
Alert level: severe
Updated on Dec 01, 2015
Alert level: severe
Updated on Oct 14, 2016
Alert level: severe
Updated on Dec 07, 2016
Alert level: severe
Updated on Jan 09, 2016
Alert level: severe
Updated on Aug 13, 2018
Alert level: severe
Updated on Sep 28, 2018
Alert level: severe
Updated on Sep 07, 2023
Alert level: severe
Updated on Sep 09, 2014

Microsoft Defender Antivirus detects and removes this threat.

This threat uses an infected Microsoft Office file to download ransomware and other malware onto your PC.

It can arrive on your PC as spam email attachment, usually as a Word file (.doc).

As part of our continued efforts to tackle entire classes of threats, Office 365 client applications now integrate with Antimalware Scan Interface (AMSI), enabling Windows Defender ATP and other security solutions to scan macros and other scripts at runtime to check for malicious behavior. Learn how this integration exposes malicious intent even with heavy obfuscation: Office VBA + AMSI: Parting the veil on malicious macros.

 

 

Alert level: severe
Updated on Sep 09, 2014

Microsoft Defender Antivirus detects and removes this threat.

This threat uses an infected Microsoft Office file to download ransomware and other malware onto your PC.

It can arrive on your PC as spam email attachment, usually as a Word file (.doc).

As part of our continued efforts to tackle entire classes of threats, Office 365 client applications now integrate with Antimalware Scan Interface (AMSI), enabling Windows Defender ATP and other security solutions to scan macros and other scripts at runtime to check for malicious behavior. Learn how this integration exposes malicious intent even with heavy obfuscation: Office VBA + AMSI: Parting the veil on malicious macros.

Alert level: severe
Updated on Nov 18, 2015
Alert level: severe
Updated on Jun 26, 2017
Alert level: severe
Updated on Sep 05, 2017
Alert level: severe