Sandbox emulates macro-enabled DOCM attack chain
Qakbot and Emotet operators have long used macro-enabled Office attachments as their initial access: a convincing invoice whose AutoOpen macro checks the victim's language (geofencing), sleeps to dodge sandbox heuristics, then launches PowerShell to beacon out and drop next-stage files. This demo rebuilds that exact chain in a benign .docm: the obfuscated macro writes a temp file, makes an HTTP request, and spawns two PowerShell stages that drop files under %APPDATA% and open the calculator as the visible impact. No real malware is involved, every payload is a benign placeholder. Submit the document to MetaDefender Aether and the emulation tree shows winword.exe spawning powershell.exe, the network beacons, and the file drops — exactly the picture analysts see for real Qakbot and Emotet lures.
Attack Technique
Spearphishing attachment with macro payload (T1566.001 / T1204.002)
MITRE ATT&CK
T1204.002 ↗Platforms
File Types
MetaDefender Capabilities