
Old Emotet Macro Pairs With Barely-Flagged New Infrastructure
A trojan.w97m/emotet Word document with anti-sandbox stalling and an 8/8 malicious sandbox consensus is riding alongside two freshly-certificated domains that detection engines have barely touched. The malware is six years old and well-signatured; the web infrastructure around it is new, thinly-flagged, and only loosely linked by a matching 89-day certificate cadence.
A Word document flagged trojan.w97m/emotet doesn't just drop a payload — it stalls first. Sandbox tags on the sample read like a checklist for frustrating automated analysis: auto-open, detect-debug-environment, long-sleeps, calls-wmi. Put together, they describe a VBA macro that fires the instant the document opens [T1204.002], then deliberately pauses and probes its environment for signs of virtualization or debugging before doing anything else [T1497].
Members-only article
This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.
Sign in to read