BIOC
Informational
✕
Office process spawns verclsid.exe
A Microsoft Office process launching verclsid.exe may be a sign of phishing.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Initial Access (TA0001)
ATT&CK techniques: Phishing: Spearphishing Attachment (T1566.001)
Indicator:
Process action type = execution AND target process name = verclsid.exe Process initiated by = winword.exe , excel.exe , powerpnt.exe
Preventable: yes