Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2b6827653e189b7e…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: fbe372b7aecab76d6d416ac1760dc435 SHA-1: 1d24af4699bd66c8ea7b9f832deb976ff7339aaa SHA-256: 2b6827653e189b7e32282c3c0a1c0c87e1182c21d8b3e07212c19e88bf846ac6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: User Execution

The file is identified by ClamAV as a known dropper for malicious content. The heuristic firing indicates that this Excel document is likely intended to download and execute a secondary payload, a common tactic for Qbot-related malware. Further analysis of the dropped payload would be required for a more specific family attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0