HTTP: Suspicious MACROCHECK OLE Document

This signature detects attempts to download suspicious Microsoft OLE documents that contain MACROCHECK credential stealer embedded in them. Such documents might compromise the targeted host.

Short Name
HTTP:MACROCHECK-DOCUMENT
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Document MACROCHECK OLE Suspicious
Release Date
01/21/2015
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?