MB-7021091424e2949c628a5a30b005cc8b4f4d57896613204d15a06815921c8987
high
📛 Threat Title
Unknown: SecuriteInfo.com.X97M.DownLoader.2343.6859.19925
Description
File type: xlsx. Size: 806912 bytes. Tags: CVE-2017-0199, xlsx. Reporter: SecuriteInfoCom. First seen: 2026-09-24 08:18:06.
Indicators of Compromise (3)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
hash_sha256
7021091424e2949c628a5a30b005cc8b4f4d57896613204d15a06815921c8987
IOC database
- Type
- hash_sha256
- Value
7021091424e2949c628a5a30b005cc8b4f4d57896613204d15a06815921c8987- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Unknown
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_sha1
90c7fc8d17955f3ffbc9322fd88e3244d89197b0
IOC database
- Type
- hash_sha1
- Value
90c7fc8d17955f3ffbc9322fd88e3244d89197b0- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
hash_md5
9b960842391ddc5f2a72c1bee9ee358f
IOC database
- Type
- hash_md5
- Value
9b960842391ddc5f2a72c1bee9ee358f- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
References (1)
-
MalwareBazaar sample page
Abuse.ch
File type: xlsx. Size: 806912 bytes. Tags: CVE-2017-0199, xlsx. Reporter: SecuriteInfoCom. First seen: 2026-09-24 08:18:06.
Remediations (10)
-
web:any.run
Online sandbox report for SecuriteInfo.com.X97M.DownLoader.901.24222.32295, tagged as macros, macros40, emotet-doc, emotet, opendir, loader, verdict: Malicious activity
-
web:any.run
Online sandbox report for SecuriteInfo.com.W97M.DownLoader.5028.13042.16836, tagged as macros, macros-on-open, emotet-doc, emotet, generated-doc, trojan, verdict ...
-
web:app.any.run
Interactive malware hunting service. Live testing of most type of threats in any environments. No installation and no waiting necessary.
-
web:app.docguard.io
General information about file Save as Image File Name SecuriteInfo.com.X97M.DownLoader.2343.6861.1515.xlsx Verdict Malicious File Type
-
web:vms.drweb.com
X97M.DownLoader.2189 Added to the Dr.Web virus database: 2025-10-03 Virus description added: 2025-10-04
-
web:vms.drweb.com
Added to the Dr.Web virus database:2026-03-23
-
web:www.joesandbox.com
Deep Malware Analysis - Joe Sandbox Analysis Report Loading Joe Sandbox Report ... Play interactive tourEdit tour Windows Analysis Report SecuriteInfo.com.X97M.DownLoader.1002.19760.28532
-
web:www.joesandbox.com
Loading Joe Sandbox Report ... Play interactive tourEdit tour Windows Analysis Report SecuriteInfo.com.X97M.DownLoader.1097.11543.23470.xls
-
web:www.microsoft.com
Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.
-
web:www.trendmicro.com
This Trojan arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.However, as of this writing, the said sites are inaccessible.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.