Classification: Malicious
doc_CE43216.doc is a malicious file sample. Reported by 2 threat sources, last seen 2026-09-02. Detected by 20 antivirus engines.
Detection summary
- 20 antivirus detections
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Suspicious Sample |
Triage |
2026-09-02 12:24:16 |
2026-09-02 12:24:16 |
anomalous-activity
|
|
| Generic.Malware |
Abuse.ch |
2020-08-21 21:16:08 |
2020-08-21 21:16:08 |
|
|
Sample information
- Filenames
- doc_CE43216.doc, emotet_e1_42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bb_2020-08-21__211556._doc
- File type
- application/msword
- MD5
9b441b317be0b128fec97cd0cf7445b6
- SHA-1
d9bd02d2c378133fac287c35a5a61cfbbc298aec
- SHA-256
42cd1526e8dc5c2eb9e1cd5aa13c9dd5068358c7f29defbac1a97b67f59b36bb
- First indexed
- 2020-08-21 22:15:05
- Last updated
- 2026-09-02 12:57:58
Antivirus detections
| Engine | Detection |
| Elastic | malicious (high confidence) |
| Cyren | W97M/Downldr.IE.gen!Eldorado |
| Symantec | ISB.Downloader!gen92 |
| TrendMicro-HouseCall | TROJ_GEN.F04IE00HL20 |
| ClamAV | Doc.Dropper.EmotetIOS-9402070-0 |
| Kaspersky | HEUR:Trojan.MSOffice.SAgent.gen |
| Rising | [email protected] (VBA) |
| Emsisoft | Trojan-Downloader.Macro.Generic.AL (A) |
| F-Secure | Malware.W97M/Agent.0034911 |
| TrendMicro | Trojan.W97M.POWLOAD.THHBABO |
| Avira | W97M/Agent.0034911 |
| ZoneAlarm | HEUR:Trojan.MSOffice.SAgent.gen |
| AhnLab-V3 | Downloader/DOC.Emotet.S1279 |
| McAfee | W97M/Downloader.ddv |
| Zoner | Probably Heur.W97Obfuscated |
| ESET-NOD32 | a variant of VBA/TrojanDownloader.Agent.UCZ |
| Tencent | Heur.Macro.Generic.h.1b4e66d5 |
| Fortinet | VBA/Agent.GC!tr.dldr |
| AVG | Script:SNH-gen [Trj] |
| Qihoo-360 | virus.office.qexvmc.1085 |