
Six-Year-Old Emotet Macro Doc Still Evades a Third of AV Engines
A 2020-vintage Word macro downloader tagged to the Emotet family draws 46 of 77 AV detections but a unanimous 3/3 malicious verdict from three sandboxes. Two domains flagged alongside it share only registrar and mail-routing convention, not a common operator.
A macro-enabled Word document that first surfaced in October 2020 is still doing exactly what it was built to do: get opened, auto-run its embedded VBA project, and quietly hand off to a follow-on payload — while nearly a quarter of the antivirus industry either misses it outright or can't parse the file at all. The sample, carrying the threat label "downloader.w97m/emotet," draws 46 flags out of 77 engines and a unanimous 3-for-3 malicious verdict across three separate sandboxes.
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read