FILEMembers
FILE

Word document’s download loop led to executables with different hashes

A recorded PowerShell command defines a download-and-launch loop, while sandbox reports show an executable response, matching artifacts and a launched file. Across reports, the same output pathname held different content, so the recurring filename does not identify a single payload.

Oct 9, 2026, 15:34 (UTC+9)Last seenOct 9, 2026Severity100ByCTX TeamActorEmotet GroupTA542IOC12RegionsAU

A web request in a Word-document sandbox analysis received an HTTP 200 response offering an executable attachment. The same report recorded an artifact under the attachment’s name, identical file content at a different local pathname, and a PowerShell child process bearing that local name. The question is no longer simply whether the document was malicious: how closely can its instructions, network activity and executable output be connected?

Members only

Members-only article

This story is members-only. Sign in to read the full body, indicators of compromise, and VirusTotal context.

Sign in to read
Source: CTX Threat Intelligence