Malicious Office (OOXML) — malware analysis report

Static analysis result for SHA-256 24df91c68cf1407f…

MALICIOUS

Office (OOXML)

9.0 KB Created: 2017-10-26 07:56:11 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2022-07-25
MD5: 34e19d3f0d833706d751361cf0681207 SHA-1: 83c583919d9af02c4472d8b0d68ba2fb94531f29 SHA-256: 24df91c68cf1407f7cbb272979371574724b58a0de8b30beb1329a4879229e56
120 Risk Score

Heuristics 2

  • ClamAV: Doc.Dropper.Agent-6423249-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-6423249-0
  • Spreadsheet DDE link launches a dangerous command critical OOXML_SPREADSHEET_DDE_MALICIOUS
    Excel workbook contains an externalLinks/ddeLink entry whose ddeService/ddeTopic launches a dangerous executable. This is SpreadsheetML DDE command execution, distinct from WordprocessingML DDE field instructions.