.. /.Wbk

Phishing
Double Click
Macros

Contributors:

mr.d0x

Description:

WBK is a Microsoft Word Backup Document. It can be used to execute malicious macros.

OS:

Windows

Recommendation:

Disable macros via GPO and whitelist the users that are permitted to run macros. For end users, turn off macros from Word's settings.

Resources:

File Samples:

https://www.hybrid-analysis.com/sample/bb0ffc8cd1fc4d83510ae0f5d6de5fa471c49067dd4479307ef5321883660b6f/5e9f3622f76b203f855a418c