files_06.20.doc

Classification: Malicious

files_06.20.doc is a malicious file sample. Linked to Valak malware. Reported by 1 threat source, last seen 2020-06-10. Detected by 29 antivirus engines.

Detection summary

  • 29 antivirus detections
  • 0 IDS alerts
  • 0 processes observed
  • 0 contacted hosts
  • 0 DNS requests

MITRE ATT&CK associations

Malware families: VALAK (S0476)

Blacklist sightings

Description Source First seen Last seen Labels MITRE ATT&CK
Valak Abuse.ch 2020-06-10 10:22:58 2020-06-10 10:22:58 S0476 Valak

Sample information

Filenames
files_06.20.doc
File type
application/vnd.openxmlformats-officedocument.wordprocessingml.document
MD5
922fdadf9db13b515e5c1a670a9c9f46
SHA-1
30b2f1d56a4435b053e4c0cd0192c9e1e0593c32
SHA-256
d83fd9eed64ee244b689eae0741f8c2aaf60fe25ea73677a76b50373d0e0e2bf
First indexed
2020-06-11 17:40:22
Last updated
2026-03-21 03:53:25

Antivirus detections

EngineDetection
DrWebW97M.DownLoader.4633
MicroWorld-eScanTrojan.GenericKDZ.67772
FireEyeTrojan.GenericKDZ.67772
McAfeeX97M/Downloader!E14E3879CE87
SangforMalware
SymantecISB.Downloader!gen255
AvastScript:SNH-gen [Trj]
KasperskyHEUR:Trojan-Downloader.MSOffice.SLoad.gen
BitDefenderTrojan.GenericKDZ.67772
NANO-AntivirusTrojan.Ole2.Vbs-heuristic.druvzi
AegisLabTrojan.MSWord.Generic.4!c
RisingMacro.Downloader.r (CLASSIC)
Endgamemalicious (high confidence)
EmsisoftTrojan.GenericKDZ.67772 (B)
F-SecureMalware.W97M/Dldr.Agent.nbttl
McAfee-GW-EditionBehavesLike.Downloader.cc
SentinelOneDFI - Malicious OPENXML
Aviraword/vbaProject.bin
FortinetVBA/Agent.TGM!tr.dldr
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmHEUR:Trojan-Downloader.MSOffice.SLoad.gen
MicrosoftTrojanDownloader:O97M/Obfuse.DR!MTB
CynetMalicious (score: 85)
MAXmalware (ai score=80)
Ad-AwareTrojan.GenericKDZ.67772
ESET-NOD32VBA/TrojanDownloader.Agent.TGJ
IkarusTrojan-Downloader.VBA.Valak
GDataMacro.Trojan-Downloader.Agent.ATE
AVGScript:SNH-gen [Trj]