Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 2e07386556fc65b9…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 74bf7e6c00693786eef0b62dbb31d3f8 SHA-1: ec1b5746f419d587ca74e0124b64dd411a1b8b05 SHA-256: 2e07386556fc65b956514dede44ffeefbb6d61c85790f2e1b2dbd7398a87d432
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The primary indicator of maliciousness is the ClamAV detection signature 'Xls.Dropper.QbotDocu12020-9818439-0', which strongly suggests this Excel file functions as a dropper. While no specific document body or scripts were extracted, the detection implies the file's purpose is to download and execute a malicious payload, likely leveraging a macro or exploit within the spreadsheet. Further analysis would be needed to confirm the exact execution chain and identify specific IOCs.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0