× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: 8c89fd278b1bc80637dcb145cd16fd480993ca1acc003f332dc8d32b8fbe6de0
File name: output.115187376.txt
Detection ratio: 17 / 56
Analysis date: 2019-02-09 05:04:06 UTC ( 1 month, 1 week ago ) View latest
Antivirus Result Update
Ad-Aware VB.EmoDldr.4.Gen 20190209
Avast Script:SNH-gen [Trj] 20190209
AVG Script:SNH-gen [Trj] 20190209
BitDefender VB.EmoDldr.4.Gen 20190209
Fortinet VBA/Agent.RTW!tr.dldr 20190209
GData VB.EmoDldr.4.Gen 20190209
Ikarus Trojan-Downloader.VBA.Agent 20190208
K7AntiVirus Trojan ( 005464381 ) 20190208
K7GW Trojan ( 005464381 ) 20190209
MAX malware (ai score=80) 20190209
McAfee W97M/Downloader.cqc 20190209
McAfee-GW-Edition W97M/Downloader.cqc 20190208
NANO-Antivirus Trojan.Ole2.Vbs-heuristic.druvzi 20190209
TACHYON Suspicious/XML.Obfus.Gen.6 20190209
Tencent Heur.Macro.Generic.Gen.h 20190209
TrendMicro Trojan.W97M.POWLOAD.TIHAOHBI 20190209
Zoner Probably MacroXML 20190209
Acronis 20190208
AegisLab 20190209
AhnLab-V3 20190208
Alibaba 20180921
Antiy-AVL 20190209
Arcabit 20190208
Avast-Mobile 20190208
Avira (no cloud) 20190208
Babable 20180918
Baidu 20190202
Bkav 20190201
CAT-QuickHeal 20190208
ClamAV 20190208
CMC 20190208
Comodo 20190209
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190209
Cyren 20190209
DrWeb 20190209
eGambit 20190209
Emsisoft 20190209
Endgame 20181108
ESET-NOD32 20190209
F-Prot 20190209
F-Secure 20190209
Sophos ML 20181128
Jiangmin 20190209
Kaspersky 20190209
Kingsoft 20190209
Malwarebytes 20190209
Microsoft 20190209
eScan 20190209
Palo Alto Networks (Known Signatures) 20190209
Panda 20190208
Qihoo-360 20190209
Rising 20190209
SentinelOne (Static ML) 20190203
Sophos AV 20190209
SUPERAntiSpyware 20190206
Symantec 20190209
Symantec Mobile Insight 20190207
TheHacker 20190203
TotalDefense 20190206
Trapmine 20190123
TrendMicro-HouseCall 20190209
Trustlook 20190209
VBA32 20190208
ViRobot 20190208
Webroot 20190209
Yandex 20190208
Zillya 20190208
ZoneAlarm by Check Point 20190209
File identification
MD5 5cc2bc9838c0ed5d430647a47aeea820
SHA1 432b37a901e414337fbaf501c1c385b20f15f82e
SHA256 8c89fd278b1bc80637dcb145cd16fd480993ca1acc003f332dc8d32b8fbe6de0
ssdeep
3072:WoUupEHY0iB4sVej0KpghkfVdJvLuL76jJG+6RWajL/xSu90OoiLuDKZXfwKelj8:Qu0iojTgmj5LW76dl6RWIxUOmD+XfwLA

File size 280.8 KB ( 287590 bytes )
File type XML
Magic literal
XML document text

TrID Microsoft Office XML Flat File Format Word Document (ASCII) (65.1%)
Microsoft Office XML Flat File Format (ASCII) (31.0%)
Generic XML (ASCII) (2.3%)
HyperText Markup Language (1.4%)
Tags
xml

VirusTotal metadata
First submission 2019-02-09 05:04:06 UTC ( 1 month, 1 week ago )
Last submission 2019-03-04 03:55:12 UTC ( 2 weeks, 5 days ago )
File names emotet_e1_8c89fd278b1bc80637dcb145cd16fd480993ca1acc003f332dc8d32b8fbe6de0_2019-02-09__050006.doc
virussign.com_5cc2bc9838c0ed5d430647a47aeea820.vir
output.115187376.txt
ExifTool file metadata
WordDocumentFontsFontPitchVal
variable

WordDocumentBodySectPRPictShapeType
#_x0000_t75

WordDocumentBodySectPRPictShapeStyle
width:468pt;height:349.5pt;visibility:visible;mso-wrap-style:square

WordDocumentDocumentPropertiesCharacters
12

WordDocumentBodySectSectPrPgMarBottom
1440

WordDocumentStylesStyleNameVal
Normal

WordDocumentStylesStyleRPrLangBidi
AR-SA

WordDocumentBodySectPRPictShapetypeId
_x0000_t75

MIMEType
application/xml

WordDocumentStylesStyleTblPrTblCellMarTopType
dxa

WordDocumentBodySectPRPictShapeSpid
_x0000_i1025

WordDocumentStylesStyleRsidVal
005A24B1

WordDocumentBodySectPRPictShapetypePathConnecttype
rect

WordDocumentBodySectSectPrPgMarRight
1440

WordDocumentShapeDefaultsShapelayoutIdmapExt
edit

WordDocumentBodySectPRPictShapetypePathExtrusionok
f

WordDocumentShapeDefaultsShapedefaultsExt
edit

WordDocumentBodySectPRPictShapeId
Picture 1

WordDocumentStylesStyleTblPrTblCellMarRightType
dxa

WordDocumentFontsFontName
Times New Roman

WordDocumentBodySectPRPictShapetypeFormulasFEqn
if lineDrawn pixelLineWidth 0

WordDocumentStylesStyleTblPrTblCellMarTopW
0

WordDocumentFontsDefaultFontsCs
Times New Roman

WordDocumentBodySectPRPictShapetypeLockAspectratio
t

WordDocumentStylesStylePPrSpacingLine
259

WordDocumentDocSuppDataBinDataName
zriZRma

WordDocumentDocPrZoomPercent
100

WordDocumentBodySectSectPrPgSzH
15840

WordDocumentFontsDefaultFontsAscii
Calibri

WordDocumentStylesStyleStyleId
Normal

WordDocumentBodySectSectPrPgSzW
12240

WordDocumentBodySectPRPictShapetypePreferrelative
t

WordDocumentStylesStylePPrSpacingAfter
160

WordDocumentOcxPresent
no

WordDocumentStylesStyleTblPrTblIndType
dxa

WordDocumentDocPrRsidsRsidRootVal
005E6EE1

WordDocumentDocumentPropertiesLastSaved
2019:02:08 21:27:00Z

WordDocumentBodySectPRPictShapetypeLockExt
edit

WordDocumentBodySectSectPrPgMarLeft
1440

WordDocumentBodySectSectPrColsSpace
720

FileType
XML

WordDocumentDocumentPropertiesPages
1

WordDocumentStylesLatentStylesLsdExceptionName
Normal

WordDocumentStylesStyleTblPrTblCellMarRightW
108

WordDocumentDocPrDefaultTabStopVal
720

WordDocumentDocumentPropertiesRevision
1

WordDocumentBodySectSectPrPgMarFooter
720

WordDocumentDocumentPropertiesTotalTime
0

WordDocumentBodySectSectPrPgMarTop
1440

WordDocumentStylesStyleUiNameVal
Table Normal

WordDocumentBodySectSectPrPgMarHeader
720

WordDocumentDocumentPropertiesParagraphs
1

WordDocumentBodySectPRRsidRPr
00E73302

WordDocumentBodySectPRsidR
00340AD4

WordDocumentBodySectPRPictShapetypeStroked
f

WordDocumentBodySectPRPictShapetypeCoordsize
21600,21600

WordDocumentDocPrCharacterSpacingControlVal
DontCompress

WordDocumentEmbeddedObjPresent
no

WordDocumentStylesStyleRPrRFontsAscii
Tahoma

WordDocumentStylesVersionOfBuiltInStylenamesVal
7

WordDocumentIgnoreSubtreeVal
http://schemas.microsoft.com/office/word/2003/wordml/sp2

WordDocumentBodySectPRPictBinData
(Binary data 145376 bytes, use -b option to extract)

WordDocumentStylesStyleTblPrTblCellMarBottomType
dxa

WordDocumentFontsFontCharsetVal
00

WordDocumentDocumentPropertiesLines
1

WordDocumentStylesStyleTblPrTblCellMarBottomW
0

WordDocumentStylesLatentStylesDefLockedState
off

WordDocumentDocPrRsidsRsidVal
00340AD4

WordDocumentBodySectPRPictShapetypeFilled
f

WordDocumentBodySectPRPictShapeImagedataSrc
wordml://FnjuawG7BfBiB6

WordDocumentBodySectPRPictShapetypeStrokeJoinstyle
miter

WordDocumentDocumentPropertiesCharactersWithSpaces
12

WordDocumentStylesStyleLinkVal
BalloonTextChar

WordDocumentStylesLatentStylesLatentStyleCount
375

WordDocumentDocPrAlwaysShowPlaceholderTextVal
off

WordDocumentBodySectPRPictShapetypePath
m@4@5l@4@11@9@11@9@5xe

WordDocumentDocumentPropertiesCreated
2019:02:08 21:27:00Z

WordDocumentStylesStyleRPrRFontsCs
Tahoma

WordDocumentBodySectSectPrPgMarGutter
0

WordDocumentDocPrViewVal
print

WordDocumentBodySectPRsidRDefault
00340AD4

WordDocumentDocSuppDataBinData
(Binary data 115748 bytes, use -b option to extract)

WordDocumentStylesStyleTblPrTblCellMarLeftW
108

WordDocumentMacrosPresent
yes

WordDocumentFontsFontFamilyVal
Roman

WordDocumentStylesStyleRPrLangVal
EN-US

WordDocumentDocumentPropertiesWords
1

WordDocumentStylesStyleTblPrTblIndW
0

WordDocumentFontsDefaultFontsFareast
Calibri

WordDocumentStylesStyleRPrSzVal
22

FileTypeExtension
xml

WordDocumentShapeDefaultsShapelayoutExt
edit

WordDocumentBodySectPRPictShapetypePathGradientshapeok
t

WordDocumentStylesStyleRPrLangFareast
EN-US

WordDocumentShapeDefaultsShapedefaultsSpidmax
1026

WordDocumentStylesStyleBasedOnVal
Normal

WordDocumentBodySectPRPictBinDataName
wordml://FnjuawG7BfBiB6

WordDocumentBodySectSectPrRsidR
005E6EE1

WordDocumentDocPrPixelsPerInchVal
120

WordDocumentDocPrIgnoreMixedContentVal
off

WordDocumentBodySectPRPictShapetypeSpt
75

WordDocumentStylesStyleRPrFontVal
Calibri

WordDocumentStylesStyleTblPrTblCellMarLeftType
dxa

WordDocumentDocPrSaveInvalidXMLVal
off

WordDocumentDocumentPropertiesVersion
16

WordDocumentStylesStyleDefault
on

WordDocumentShapeDefaultsShapelayoutIdmapData
1

WordDocumentStylesStyleType
paragraph

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!