Classification: Malicious
Normal.dotm is a malicious file sample. Linked to Bitter activity. Reported by 3 threat sources, last seen 2026-08-31. Detected by 14 antivirus engines.
Detection summary
- 14 antivirus detections
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Generic Malware |
Cyber Threat Alliance |
2026-08-09 10:17:22 |
2026-08-31 10:15:19 |
malicious-activity
|
|
| Bitter |
MalwareBazaar Abuse.ch |
2025-11-07 11:01:47 |
2025-11-07 11:01:47 |
malicious-activity
|
G1002 BITTER
|
| Generic Malware |
Hybrid-Analysis |
2025-09-02 18:23:22 |
2025-09-02 19:30:08 |
|
|
Sample information
- Filenames
- Normal.dotm
- File type
- Microsoft Word 2007+
- Size
- 20403 bytes
- MD5
4bedd8e2b66cc7d64b293493ef5b8942
- SHA-1
d5fc860bf59dddaac2b81e73017319a6c0dc5049
- SHA-256
a39a26838e6bc26502ff0b562a3a098d55c5ad5b6daf4405469ce5e11f2192a4
- First indexed
- 2025-09-02 18:09:54
- Last updated
- 2026-06-17 03:55:28
Antivirus detections
| Engine | Detection |
| ALYac | GT:VB.BladabindiDldr.2.7DBDDFA4 |
| Arcabit | GT:VB.BladabindiDldr.2.7DBDDFA4 |
| BitDefender | GT:VB.BladabindiDldr.2.7DBDDFA4 |
| CTX | docx.unknown.bladabindidldr |
| Elastic | malicious (high confidence) |
| Emsisoft | GT:VB.BladabindiDldr.2.7DBDDFA4 (B) |
| GData | GT:VB.BladabindiDldr.2.7DBDDFA4 |
| Google | Highly Suspicious |
| MicroWorld-eScan | GT:VB.BladabindiDldr.2.7DBDDFA4 |
| NANO-Antivirus | Trojan.Ole2.Vbs-heuristic.druvzi |
| Rising | Malware.Obfus/[email protected] (VBA) |
| SentinelOne | Static AI - Malicious OPENXML |
| TACHYON | Suspicious/WOX.XSR.Gen |
| VIPRE | GT:VB.BladabindiDldr.2.7DBDDFA4 |
Process list
| Name | Command line |
| WINWORD.EXE | /n /f "C:\Normal.dotm" |