Classification: Malicious
Normal.dotm is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 22 antivirus engines.
Detection summary
- 22 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-09-02 18:00:49 |
2026-09-02 18:00:49 |
malicious-activity
|
|
| Generic.Malware |
MalwareBazaar Abuse.ch |
2024-05-13 17:08:52 |
2024-05-13 17:08:52 |
malicious-activity
|
|
Sample information
- Filenames
- Normal.dotm
- File type
- application/vnd.openxmlformats-officedocument.wordprocessingml.document
- MD5
9c5b70c2b4cc2c38d37e4d22ca8dad9f
- SHA-1
192dd5a05df224f37df06c4d57649e1ea06c2f10
- SHA-256
0b70042cd435e30a2c2583eb62b2e4c4bd69bbefc6b9f359e0fae02dc6a3dd4e
- First indexed
- 2024-05-13 18:23:08
- Last updated
- 2024-05-13 18:23:08
Antivirus detections
| Engine | Detection |
| AVG | VBA:Gamaredon-E [Drp] |
| Acronis | suspicious |
| AhnLab-V3 | Trojan/DOC.MalVba.S2457 |
| Arcabit | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| Avast | VBA:Gamaredon-E [Drp] |
| BitDefender | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| ClamAV | Doc.Malware.Valyria-10005698-0 |
| Elastic | malicious (high confidence) |
| Emsisoft | GT:VB.Heur2.EmoooDldr.12.5138F799 (B) |
| FireEye | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| GData | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| Kaspersky | UDS:Trojan.MSOffice.SAgent.gen |
| Lionic | Trojan.MSWord.EmoooDldr.4!c |
| MAX | malware (ai score=84) |
| MicroWorld-eScan | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| Rising | Malware.Obfus/[email protected] (VBA) |
| Sangfor | VBA.Sus.Obf |
| Skyhigh | Artemis |
| VIPRE | GT:VB.Heur2.EmoooDldr.12.5138F799 |
| Varist | PP97M/Agent.BZS.gen!Eldorado |
| ZoneAlarm | UDS:Trojan.MSOffice.SAgent.gen |
| alibabacloud | Trojan:MSOffice/Heur2.Etdbh8Rkf |