× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 2b5e3397b1f6a03a26d3b722959658aac473ab0d70848922c523b7470d22d886
File name: emotet_e1_2b5e3397b1f6a03a26d3b722959658aac473ab0d70848922c523b74...
Detection ratio: 34 / 57
Analysis date: 2019-01-28 09:22:29 UTC ( 3 months, 3 weeks ago ) View latest
Antivirus Result Update
Ad-Aware Trojan.GenericKD.31541852 20190127
AhnLab-V3 MSOffice/Xprocess 20190128
ALYac Trojan.Downloader.DOC.gen 20190127
Arcabit Trojan.Generic.D1E14A5C 20190127
Avast Other:Malware-gen [Trj] 20190128
AVG Other:Malware-gen [Trj] 20190128
Avira (no cloud) W2000M/Agent.0494511 20190127
BitDefender Trojan.GenericKD.31541852 20190127
Comodo Malware@#1no6thm7btn76 20190128
Cyren XML/Trojan.EYBM-5 20190127
DrWeb W97M.DownLoader.3233 20190127
Emsisoft Trojan.GenericKD.31541852 (B) 20190127
ESET-NOD32 VBA/TrojanDownloader.Agent.MDW 20190128
F-Secure Trojan.GenericKD.31541852 20190128
Fortinet VBA/Agent.AFD!tr.dldr 20190128
GData Trojan.GenericKD.31541852 20190127
Ikarus Trojan-Downloader.VBA.Agent 20190128
K7AntiVirus Trojan ( 005464381 ) 20190127
K7GW Trojan ( 005464381 ) 20190128
Kaspersky Trojan-Downloader.MSOffice.Agent.aq 20190128
McAfee RDN/Generic Downloader.x 20190128
McAfee-GW-Edition RDN/Generic Downloader.x 20190127
Microsoft Trojan:O97M/Obfuse.CO 20190128
eScan Trojan.GenericKD.31541852 20190128
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi 20190128
Panda Trj/RnkBend.A 20190127
Qihoo-360 virus.office.qexvmc.1085 20190128
Sophos AV Troj/DocDl-RMY 20190127
Symantec Trojan.Gen.2 20190128
Tencent Office.Trojan-downloader.Agent.Wsju 20190128
TrendMicro Trojan.W97M.POWLOAD.THOBAAI 20190128
TrendMicro-HouseCall Trojan.W97M.POWLOAD.THOBAAI 20190128
VBA32 Trojan-Downloader.VBA.Agent 20190128
ZoneAlarm by Check Point Trojan-Downloader.MSOffice.Agent.aq 20190128
Acronis 20190128
AegisLab 20190128
Alibaba 20180921
Antiy-AVL 20190128
Avast-Mobile 20190127
Babable 20180917
Baidu 20190127
Bkav 20190125
CAT-QuickHeal 20190127
ClamAV 20190127
CMC 20190127
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190128
eGambit 20190128
Endgame 20181108
F-Prot 20190127
Sophos ML 20181128
Jiangmin 20190127
Kingsoft 20190128
Malwarebytes 20190127
MAX 20190128
Palo Alto Networks (Known Signatures) 20190128
Rising 20190127
SentinelOne (Static ML) 20190124
SUPERAntiSpyware 20190123
TACHYON 20190127
TheHacker 20190124
TotalDefense 20190127
Trapmine 20190123
Trustlook 20190128
ViRobot 20190128
Webroot 20190128
Yandex 20190125
Zillya 20190125
Zoner 20190125
File identification
MD5 d9762a2673af96f52637be12213dc866
SHA1 067db3879c77c2b701a5d152d8860d03a6689eb5
SHA256 2b5e3397b1f6a03a26d3b722959658aac473ab0d70848922c523b7470d22d886
ssdeep
3072:/BMqmaWfB+nAzmVBnw+K5wRvmCdvaktxL:52VMnaSn1KovmCdv/7

File size 129.2 KB ( 132331 bytes )
File type XML
Magic literal
XML document text

TrID Microsoft Office XML Flat File Format Word Document (ASCII) (60.1%)
Microsoft Office XML Flat File Format (ASCII) (28.6%)
Microsoft Extensible Application Markup Language (7.7%)
Generic XML (ASCII) (2.1%)
HyperText Markup Language (1.2%)
Tags
xml attachment

VirusTotal metadata
First submission 2019-01-18 14:17:24 UTC ( 4 months ago )
Last submission 2019-01-19 05:27:42 UTC ( 4 months ago )
File names
ORDER_DETAILS_FILE.doc
Documento.doc
190118-Untitled-1644.doc
1901_Untitled_195194.doc
012019_Untitled_1226.doc
0119-Untitled-07059.doc
190118-Untitled-099503.doc
emotet_e1_2b5e3397b1f6a03a26d3b722959658aac473ab0d70848922c523b7470d22d886_2019-01-18__14:10:03.doc
0119_Untitled_06480.doc
eFILE_Order_Details.doc
0119_Untitled_19033.doc
ExifTool file metadata
WordDocumentFontsFontPitchVal
variable

WordDocumentBodySectPRPictShapeType
#_x0000_t75

WordDocumentBodySectPRPictShapeStyle
width:442.5pt;height:132.75pt;visibility:visible;mso-wrap-style:square

WordDocumentDocumentPropertiesCharacters
69

WordDocumentBodySectSectPrPgMarBottom
1440

WordDocumentStylesStyleNameVal
Normal

WordDocumentStylesStyleRPrLangBidi
AR-SA

WordDocumentBodySectPRPictShapetypeId
_x0000_t75

WordDocumentBodySectPRPictShapetypeLockExt
edit

MIMEType
application/xml

WordDocumentStylesStyleTblPrTblCellMarTopType
dxa

WordDocumentStylesStyleRsidVal
003B0670

WordDocumentBodySectPRPictShapetypePathConnecttype
rect

WordDocumentBgPictBackgroundBgcolor
#00AEEA

WordDocumentBodySectSectPrPgMarRight
1440

WordDocumentShapeDefaultsShapelayoutIdmapExt
edit

WordDocumentBodySectPRPictShapetypePathExtrusionok
f

WordDocumentShapeDefaultsShapedefaultsExt
edit

WordDocumentBodySectPRPictShapeId
Picture 1

WordDocumentStylesStyleTblPrTblCellMarRightType
dxa

WordDocumentFontsFontName
Times New Roman

WordDocumentBodySectPRPictShapetypeFormulasFEqn
if lineDrawn pixelLineWidth 0

WordDocumentStylesStyleTblPrTblCellMarTopW
0

WordDocumentFontsDefaultFontsCs
Times New Roman

WordDocumentBodySectPRPictShapetypeLockAspectratio
t

WordDocumentStylesStylePPrSpacingLine
259

WordDocumentDocSuppDataBinDataName
editdata.mso

WordDocumentDocPrZoomPercent
100

WordDocumentBodySectSectPrPgSzH
15840

WordDocumentFontsDefaultFontsAscii
Calibri

WordDocumentStylesStyleStyleId
Normal

WordDocumentBodySectSectPrPgSzW
12240

WordDocumentBodySectPRPictShapetypePreferrelative
t

WordDocumentStylesStylePPrSpacingAfter
160

WordDocumentShapeDefaultsShapedefaultsSpidmax
1026

WordDocumentStylesStyleTblPrTblIndType
dxa

WordDocumentDocPrRsidsRsidRootVal
005E6EE1

WordDocumentDocumentPropertiesLastSaved
2019:01:18 11:14:00Z

WordDocumentBodySectPRPictShapeSpid
_x0000_i1025

WordDocumentBodySectSectPrPgMarLeft
1440

WordDocumentBodySectSectPrColsSpace
720

WordDocumentStylesStyleBasedOnVal
Normal

WordDocumentDocumentPropertiesPages
1

WordDocumentShapeDefaultsShapedefaultsColormruExt
edit

WordDocumentStylesLatentStylesLsdExceptionName
Normal

WordDocumentStylesStyleTblPrTblCellMarRightW
108

WordDocumentDocPrDefaultTabStopVal
720

WordDocumentDocumentPropertiesRevision
1

WordDocumentBodySectSectPrPgMarFooter
720

WordDocumentDocumentPropertiesTotalTime
0

WordDocumentBodySectSectPrPgMarTop
1440

WordDocumentStylesStyleUiNameVal
Table Normal

WordDocumentBodySectSectPrPgMarHeader
720

WordDocumentDocumentPropertiesParagraphs
1

WordDocumentBodySectPRRsidRPr
0095778C

WordDocumentBodySectPRsidR
00005EB7

WordDocumentBodySectPRPictShapetypeStroked
f

WordDocumentBodySectPRPictShapetypeCoordsize
21600,21600

WordDocumentDocPrCharacterSpacingControlVal
DontCompress

WordDocumentEmbeddedObjPresent
no

WordDocumentStylesStyleRPrRFontsAscii
Tahoma

WordDocumentStylesVersionOfBuiltInStylenamesVal
7

WordDocumentIgnoreSubtreeVal
http://schemas.microsoft.com/office/word/2003/wordml/sp2

WordDocumentShapeDefaultsShapedefaultsColormruColors
#00aeea

WordDocumentStylesStyleTblPrTblCellMarBottomType
dxa

WordDocumentFontsFontCharsetVal
00

WordDocumentDocumentPropertiesLines
1

WordDocumentStylesStyleTblPrTblCellMarBottomW
0

WordDocumentStylesLatentStylesDefLockedState
off

WordDocumentDocPrRsidsRsidVal
00005EB7

WordDocumentBodySectPRPictShapetypeFilled
f

WordDocumentBodySectPRPictShapeImagedataSrc
wordml://02000001.jpg

WordDocumentBodySectPRPictShapetypeStrokeJoinstyle
miter

WordDocumentDocumentPropertiesCharactersWithSpaces
80

WordDocumentStylesStyleLinkVal
BalloonTextChar

WordDocumentStylesLatentStylesLatentStyleCount
375

WordDocumentDocPrAlwaysShowPlaceholderTextVal
off

WordDocumentBodySectPRPictShapetypePath
m@4@5l@4@11@9@11@9@5xe

WordDocumentDocumentPropertiesCreated
2019:01:18 11:14:00Z

WordDocumentDocumentPropertiesVersion
16

WordDocumentBodySectSectPrPgMarGutter
0

WordDocumentDocPrViewVal
print

WordDocumentBodySectPRsidRDefault
00FB2292

WordDocumentStylesStyleTblPrTblCellMarLeftW
108

WordDocumentMacrosPresent
yes

WordDocumentFontsFontFamilyVal
Roman

WordDocumentStylesStyleRPrLangVal
EN-US

WordDocumentDocumentPropertiesWords
12

WordDocumentStylesStyleTblPrTblIndW
0

WordDocumentFontsDefaultFontsFareast
Calibri

WordDocumentStylesStyleRPrSzVal
22

FileTypeExtension
xml

WordDocumentShapeDefaultsShapelayoutIdmapData
1

WordDocumentBodySectPRPictShapetypePathGradientshapeok
t

WordDocumentStylesStyleRPrLangFareast
EN-US

WordDocumentOcxPresent
no

FileType
XML

WordDocumentBodySectPRPictBinDataName
wordml://02000001.jpg

WordDocumentBodySectSectPrRsidR
00005EB7

WordDocumentDocPrPixelsPerInchVal
120

WordDocumentDocPrIgnoreMixedContentVal
off

WordDocumentBodySectPRPictShapetypeSpt
75

WordDocumentStylesStyleRPrFontVal
Calibri

WordDocumentStylesStyleTblPrTblCellMarLeftType
dxa

WordDocumentDocPrSaveInvalidXMLVal
off

WordDocumentStylesStyleRPrRFontsCs
Tahoma

WordDocumentStylesStyleDefault
on

WordDocumentShapeDefaultsShapelayoutExt
edit

WordDocumentStylesStyleType
paragraph

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!