Page 102 - CSEW
P. 102
ESA Threat Grid File Analysis
SHA - e95aa9b18c91af38132c1af8e88c70569d4ab6a803b0382d025116ef7f3b40b0
Very high Threat Level
• File reaches out to the network
• Multiple pieces of embedded content
• Tags here are of questionable use unless
correlated with the Matching Signatures
Bad Behavior!
• Why is a PDF file opening network
connections?
• Why is it opening files?
© 2016 Engage ESM All Rights Reserved 111