Skip to main content
← Back to Demos
Macro advanced · 15 min

Sandbox emulates macro-enabled DOCM attack chain

Qakbot and Emotet operators have long used macro-enabled Office attachments as their initial access: a convincing invoice whose AutoOpen macro checks the victim's language (geofencing), sleeps to dodge sandbox heuristics, then launches PowerShell to beacon out and drop next-stage files. This demo rebuilds that exact chain in a benign .docm: the obfuscated macro writes a temp file, makes an HTTP request, and spawns two PowerShell stages that drop files under %APPDATA% and open the calculator as the visible impact. No real malware is involved, every payload is a benign placeholder. Submit the document to MetaDefender Aether and the emulation tree shows winword.exe spawning powershell.exe, the network beacons, and the file drops — exactly the picture analysts see for real Qakbot and Emotet lures.

Attack Technique

Spearphishing attachment with macro payload (T1566.001 / T1204.002)

MITRE ATT&CK

T1204.002 ↗

Platforms

linuxwindows

File Types

.docm

MetaDefender Capabilities

Adaptive Sandbox
--- ---