doc_CE43216.doc

Classification: Malicious

doc_CE43216.doc is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 20 antivirus engines.

Detection summary

  • 20 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Suspicious Sample Triage 2026-09-02 12:24:16 2026-09-02 12:24:16 anomalous-activity
Generic.Malware Abuse.ch 2020-08-21 21:16:08 2020-08-21 21:16:08

Tags

macro

Sample information

Filenames
doc_CE43216.doc, emotet_e1_42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bb_2020-08-21__211556._doc
File type
application/msword
MD5
9b441b317be0b128fec97cd0cf7445b6
SHA-1
d9bd02d2c378133fac287c35a5a61cfbbc298aec
SHA-256
42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bb
First indexed
2020-08-21 22:15:05
Last updated
2026-09-02 12:57:58

Antivirus detections

EngineDetection
Elasticmalicious (high confidence)
CyrenW97M/Downldr.IE.gen!Eldorado
SymantecISB.Downloader!gen92
TrendMicro-HouseCallTROJ_GEN.F04IE00HL20
ClamAVDoc.Dropper.EmotetIOS-9402070-0
KasperskyHEUR:Trojan.MSOffice.SAgent.gen
Rising[email protected] (VBA)
EmsisoftTrojan-Downloader.Macro.Generic.AL (A)
F-SecureMalware.W97M/Agent.0034911
TrendMicroTrojan.W97M.POWLOAD.THHBABO
AviraW97M/Agent.0034911
ZoneAlarmHEUR:Trojan.MSOffice.SAgent.gen
AhnLab-V3Downloader/DOC.Emotet.S1279
McAfeeW97M/Downloader.ddv
ZonerProbably Heur.W97Obfuscated
ESET-NOD32a variant of VBA/TrojanDownloader.Agent.UCZ
TencentHeur.Macro.Generic.h.1b4e66d5
FortinetVBA/Agent.GC!tr.dldr
AVGScript:SNH-gen [Trj]
Qihoo-360virus.office.qexvmc.1085