Analysis results

Feature Result
Verdict Malicious
File size173832 bytes
File infoComposite Document File V2 Document, Little Endian, Os: Windows, Version 6.2, Code page: 1252, Title: Qui., Author: Sacha Renard, Template: Normal.dotm, Revision Number: 1, Name of Creating Application: Microsoft Office Word, Create Time/Date: Thu Aug 6 19:32:00 2020, Last Saved Time/Date: Thu Aug 6 19:32:00 2020, Number of Pages: 1, Number of Words: 4, Number of Characters: 24, Security: 0
Matching maldoc templates Emotet ZLoader
Suspicious findings in the VBA Create showwindow Base64 Strings CreateObject Hex Strings Chr AutoExec
Malicious methods LOLBAS
First reported 16/04/2021 13:18:03
Scanning time 3.3 sec
Consult others Triage VirusTotal Hybrid Analysis