Classification: Malicious
sample.doc.vir is a malicious file sample. Linked to Squirrelwaffle malware. Reported by 1 threat source, last seen 2021-11-25.
Detection summary
- 35 antivirus detections (50% detection ratio)
- 0 IDS alerts
- 1 processes observed
- 0 contacted hosts
- 0 DNS requests
Blacklist sightings
| Description |
Source |
First seen |
Last seen |
Labels |
MITRE ATT&CK |
| Squirrelwaffle |
Abuse.ch |
2021-11-25 17:25:01 |
2021-11-25 17:25:01 |
malicious-activity
|
S1030 Squirrelwaffle
|
| Generic.Malware |
Abuse.ch |
2021-11-25 17:25:01 |
2021-11-25 17:25:01 |
malicious-activity
|
|
Sample information
- Filenames
- sample.doc.vir, 6be56f977b6692fb6ce5f94e110664e3
- File type
- application/msword
- Size
- 216577 bytes
- MD5
6be56f977b6692fb6ce5f94e110664e3
- SHA-1
f4d5ce35c656e0f156a2ced453a964faabef09fb
- SHA-256
ae94cd20505f914bba5e612acb80c429c5606a739c0838e3a5f87bfcc7cc8519
- First indexed
- 2021-11-25 07:24:39
- Last updated
- 2026-03-25 20:37:49
Antivirus detections
| Engine | Detection |
| Cynet | Malicious (score: 99) |
| CAT-QuickHeal | W97M.Downloader.44569 |
| ALYac | VB:Trojan.Valyria.5292 |
| Cyren | W97M/Agent.ACT.gen!Eldorado |
| ESET-NOD32 | a variant of VBA/TrojanDropper.Agent.CEM |
| TrendMicro-HouseCall | Trojan.W97M.DONOFF.AUJGL |
| Avast | Script:SNH-gen [Trj] |
| ClamAV | Doc.Downloader.SquirrelWaffle09210-9895192-0 |
| Kaspersky | HEUR:Trojan.MSOffice.SAgent.gen |
| BitDefender | VB:Trojan.Valyria.5292 |
| NANO-Antivirus | Trojan.Ole2.Vbs-heuristic.druvzi |
| MicroWorld-eScan | VB:Trojan.Valyria.5292 |
| Ad-Aware | VB:Trojan.Valyria.5292 |
| Sophos | Troj/DocDrp-AFT |
| TrendMicro | Trojan.W97M.DONOFF.SME |
| McAfee-GW-Edition | BehavesLike.OLE2.Downloader.dg |
| FireEye | VB:Trojan.Valyria.5292 |
| Emsisoft | VB:Trojan.Valyria.5292 (B) |
| Ikarus | Trojan-Downloader.VBA.Agent |
| GData | VB:Trojan.Valyria.5292 |
| Avira | W97M/Agent.9761513 |
| MAX | malware (ai score=80) |
| Antiy-AVL | Trojan/Generic.ASMacro.2E006 |
| Arcabit | HEUR.VBA.Trojan.d |
| Microsoft | Trojan:O97M/Donoff.RM!MTB |
| McAfee | W97M/Dropper.il |
| TACHYON | Suspicious/W97M.DRP.Gen |
| VBA32 | TrojanDownloader.O97M.Powdow.SM |
| Fortinet | VBA/Agent.9F19!tr |
| AVG | Script:SNH-gen [Trj] |
| Lionic | Trojan.MSOffice.SAgent.4!c |
| Symantec | Trojan.Gen.NPE |
| Tencent | Win32.Trojan.Valyria.Wteb |
| DrWeb | Exploit.Siggen3.22361 |
| Ikarus | Win32.Outbreak |
Process list
| Name | Command line |
| WINWORD.EXE | /n "C:\6be56f977b6692fb6ce5f94e110664e3.doc" |