× Cookies are disabled! This site requires cookies to be enabled to work properly
SHA256: c31ba6c3131c3c7132790871f023e8e40c0132d3793ad8f4e292f8c2108a7476
File name: emotet_e1_c31ba6c3131c3c7132790871f023e8e40c0132d3793ad8f4e292f8c...
Detection ratio: 26 / 57
Analysis date: 2019-02-16 00:59:16 UTC ( 2 months ago ) View latest
Antivirus Result Update
Ad-Aware Trojan.Agent.DPNI 20190215
ALYac Trojan.Agent.DPNI 20190215
Arcabit Trojan.Agent.DPNI 20190215
Avira (no cloud) W2000M/Agent.0143212 20190215
Baidu VBA.Trojan-Downloader.Agent.edr 20190214
BitDefender Trojan.Agent.DPNI 20190215
ClamAV Doc.Downloader.Emotet-6856719-0 20190215
Cyren W97M/Downldr.BJ.gen!Eldorado 20190215
Emsisoft Trojan.Agent.DPNI (B) 20190215
ESET-NOD32 VBA/TrojanDownloader.Agent.MRT 20190215
F-Secure Malware.W2000M/Agent.0143212 20190215
Fortinet VBA/Agent.MPF!tr.dldr 20190215
GData Generic.Trojan.Agent.AKQ@susp 20190215
Ikarus Trojan-Downloader.VBA.Agent 20190215
K7AntiVirus Trojan ( 005464381 ) 20190215
K7GW Trojan ( 005464381 ) 20190215
Kaspersky HEUR:Trojan.MSOffice.SAgent.gen 20190215
McAfee W97M/Downloader.cqc 20190215
McAfee-GW-Edition W97M/Downloader.cqc 20190215
Microsoft TrojanDownloader:O97M/Donoff 20190215
eScan Trojan.Agent.DPNI 20190215
Sophos AV Troj/DocDl-SBT 20190215
Symantec Trojan.Gen.2 20190215
Tencent Win32.Trojan-downloader.Agent.Pauw 20190215
ZoneAlarm by Check Point HEUR:Trojan.MSOffice.SAgent.gen 20190215
Zoner Probably MacroXML 20190215
Acronis 20190213
AegisLab 20190215
AhnLab-V3 20190215
Alibaba 20180921
Antiy-AVL 20190215
Avast 20190215
Avast-Mobile 20190215
AVG 20190215
Babable 20180917
Bkav 20190214
CAT-QuickHeal 20190215
CMC 20190215
Comodo 20190215
CrowdStrike Falcon (ML) 20181023
Cybereason 20190109
Cylance 20190215
DrWeb 20190215
eGambit 20190215
Endgame 20190215
F-Prot 20190215
Sophos ML 20181128
Jiangmin 20190215
Kingsoft 20190215
Malwarebytes 20190215
MAX 20190217
NANO-Antivirus 20190215
Palo Alto Networks (Known Signatures) 20190215
Panda 20190215
Qihoo-360 20190215
Rising 20190215
SentinelOne (Static ML) 20190203
SUPERAntiSpyware 20190213
Symantec Mobile Insight 20190206
TACHYON 20190215
TheHacker 20190215
TotalDefense 20190215
Trapmine 20190123
TrendMicro 20190215
TrendMicro-HouseCall 20190215
Trustlook 20190215
VBA32 20190215
ViRobot 20190215
Webroot 20190215
Yandex 20190215
Zillya 20190215
File identification
MD5 b10646dfd3979c83019d70b1f17e5d4f
SHA1 a9e77313444de33453d89451e2d702e2901d626f
SHA256 c31ba6c3131c3c7132790871f023e8e40c0132d3793ad8f4e292f8c2108a7476
ssdeep
3072:4Nuje9H1visYgKUonh55BNDlqFfBC8QluuuJSeCCheHP91sjEwc9KJfeWZiH:CJ1DYgKvn75LY6c7EeCChevXlwc9Ky

File size 302.9 KB ( 310168 bytes )
File type XML
Magic literal
XML document text

TrID Microsoft Office XML Flat File Format Word Document (ASCII) (61.8%)
Microsoft Office XML Flat File Format (ASCII) (29.4%)
Outline Processor Markup Language (5.1%)
Generic XML (ASCII) (2.2%)
HyperText Markup Language (1.3%)
Tags
xml

VirusTotal metadata
First submission 2019-02-15 21:42:25 UTC ( 2 months ago )
Last submission 2019-02-16 00:59:16 UTC ( 2 months ago )
File names emotet_e1_c31ba6c3131c3c7132790871f023e8e40c0132d3793ad8f4e292f8c2108a7476_2019-02-15__040503.doc
.
ExifTool file metadata
WordDocumentFontsFontPitchVal
variable

WordDocumentBodySectPRPictShapeType
#_x0000_t75

WordDocumentBodySectPRPictShapeStyle
width:468pt;height:349.5pt;visibility:visible;mso-wrap-style:square

WordDocumentDocumentPropertiesCharacters
1

WordDocumentBodySectSectPrPgMarBottom
1440

WordDocumentStylesStyleNameVal
Normal

WordDocumentStylesStyleRPrLangBidi
AR-SA

WordDocumentBodySectPRPictShapetypeId
_x0000_t75

MIMEType
application/xml

WordDocumentStylesStyleTblPrTblCellMarTopType
dxa

WordDocumentBodySectPRPictShapeSpid
_x0000_i1025

WordDocumentStylesStyleRsidVal
005A24B1

WordDocumentBodySectPRPictShapetypePathConnecttype
rect

WordDocumentBodySectSectPrPgMarRight
1440

WordDocumentShapeDefaultsShapelayoutIdmapExt
edit

WordDocumentBodySectPRPictShapetypePathExtrusionok
f

WordDocumentShapeDefaultsShapedefaultsExt
edit

WordDocumentBodySectPRPictShapeId
Picture 1

WordDocumentStylesStyleTblPrTblCellMarRightType
dxa

WordDocumentFontsFontName
Times New Roman

WordDocumentBodySectPRPictShapetypeFormulasFEqn
if lineDrawn pixelLineWidth 0

WordDocumentStylesStyleTblPrTblCellMarTopW
0

WordDocumentFontsDefaultFontsCs
Times New Roman

WordDocumentBodySectPRPictShapetypeLockAspectratio
t

WordDocumentStylesStylePPrSpacingLine
259

WordDocumentDocSuppDataBinDataName
s3_41_7

WordDocumentDocPrZoomPercent
100

WordDocumentBodySectSectPrPgSzH
15840

WordDocumentFontsDefaultFontsAscii
Calibri

WordDocumentStylesStyleStyleId
Normal

WordDocumentBodySectSectPrPgSzW
12240

WordDocumentBodySectPRPictShapetypePreferrelative
t

WordDocumentStylesStylePPrSpacingAfter
160

WordDocumentOcxPresent
no

WordDocumentStylesStyleTblPrTblIndType
dxa

WordDocumentDocPrRsidsRsidRootVal
005E6EE1

WordDocumentDocumentPropertiesLastSaved
2019:02:14 19:21:00Z

WordDocumentBodySectPRPictShapetypeLockExt
edit

WordDocumentBodySectSectPrPgMarLeft
1440

WordDocumentBodySectSectPrColsSpace
720

FileType
XML

WordDocumentDocumentPropertiesPages
1

WordDocumentStylesLatentStylesLsdExceptionName
Normal

WordDocumentStylesStyleTblPrTblCellMarRightW
108

WordDocumentDocPrDefaultTabStopVal
720

WordDocumentDocumentPropertiesRevision
1

WordDocumentBodySectSectPrPgMarFooter
720

WordDocumentDocumentPropertiesTotalTime
0

WordDocumentBodySectSectPrPgMarTop
1440

WordDocumentStylesStyleUiNameVal
Table Normal

WordDocumentBodySectSectPrPgMarHeader
720

WordDocumentDocumentPropertiesParagraphs
1

WordDocumentBodySectPRRsidRPr
00CD1998

WordDocumentBodySectPRsidR
005E6EE1

WordDocumentBodySectPRPictShapetypeStroked
f

WordDocumentBodySectPRPictShapetypeCoordsize
21600,21600

WordDocumentDocPrCharacterSpacingControlVal
DontCompress

WordDocumentEmbeddedObjPresent
no

WordDocumentStylesStyleRPrRFontsAscii
Tahoma

WordDocumentStylesVersionOfBuiltInStylenamesVal
7

WordDocumentIgnoreSubtreeVal
http://schemas.microsoft.com/office/word/2003/wordml/sp2

WordDocumentBodySectPRPictBinData
(Binary data 175386 bytes, use -b option to extract)

WordDocumentStylesStyleTblPrTblCellMarBottomType
dxa

WordDocumentFontsFontCharsetVal
00

WordDocumentDocumentPropertiesLines
1

WordDocumentStylesStyleTblPrTblCellMarBottomW
0

WordDocumentStylesLatentStylesDefLockedState
off

WordDocumentDocPrRsidsRsidVal
005A24B1

WordDocumentBodySectPRPictShapetypeFilled
f

WordDocumentBodySectPRPictShapeImagedataSrc
wordml://R38_93.U_3_3_04.W24_0597

WordDocumentBodySectPRPictShapetypeStrokeJoinstyle
miter

WordDocumentDocumentPropertiesCharactersWithSpaces
1

WordDocumentStylesStyleLinkVal
BalloonTextChar

WordDocumentStylesLatentStylesLatentStyleCount
375

WordDocumentDocPrAlwaysShowPlaceholderTextVal
off

WordDocumentBodySectPRPictShapetypePath
m@4@5l@4@11@9@11@9@5xe

WordDocumentDocumentPropertiesCreated
2019:02:14 19:21:00Z

WordDocumentStylesStyleRPrRFontsCs
Tahoma

WordDocumentBodySectSectPrPgMarGutter
0

WordDocumentDocPrViewVal
print

WordDocumentBodySectPRsidRDefault
00A60D66

WordDocumentDocSuppDataBinData
(Binary data 95658 bytes, use -b option to extract)

WordDocumentStylesStyleTblPrTblCellMarLeftW
108

WordDocumentMacrosPresent
yes

WordDocumentFontsFontFamilyVal
Roman

WordDocumentStylesStyleRPrLangVal
EN-US

WordDocumentDocumentPropertiesWords
0

WordDocumentStylesStyleTblPrTblIndW
0

WordDocumentFontsDefaultFontsFareast
Calibri

WordDocumentStylesStyleRPrSzVal
22

FileTypeExtension
xml

WordDocumentShapeDefaultsShapelayoutExt
edit

WordDocumentBodySectPRPictShapetypePathGradientshapeok
t

WordDocumentStylesStyleRPrLangFareast
EN-US

WordDocumentShapeDefaultsShapedefaultsSpidmax
1026

WordDocumentStylesStyleBasedOnVal
Normal

WordDocumentBodySectPRPictBinDataName
wordml://R38_93.U_3_3_04.W24_0597

WordDocumentBodySectSectPrRsidR
005E6EE1

WordDocumentDocPrPixelsPerInchVal
120

WordDocumentDocPrIgnoreMixedContentVal
off

WordDocumentBodySectPRPictShapetypeSpt
75

WordDocumentStylesStyleRPrFontVal
Calibri

WordDocumentStylesStyleTblPrTblCellMarLeftType
dxa

WordDocumentDocPrSaveInvalidXMLVal
off

WordDocumentDocumentPropertiesVersion
16

WordDocumentStylesStyleDefault
on

WordDocumentShapeDefaultsShapelayoutIdmapData
1

WordDocumentStylesStyleType
paragraph

No comments. No VirusTotal Community member has commented on this item yet, be the first one to do so!

Leave your comment...

?
Post comment

You have not signed in. Only registered users can leave comments, sign in and have a voice!

No votes. No one has voted on this item yet, be the first one to do so!