Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 32f814d945f216cb…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: e252e5d503bea19b95fb4fe1a9bca698 SHA-1: 86958cd215eb2eb14b59d6cfd980de4b31aa0492 SHA-256: 32f814d945f216cb9ad16877fc1dcf7bec8eec5b776a491153bfefa052f513e6
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File

The file is an Excel document flagged by ClamAV as a dropper, indicating its primary purpose is to deliver other malware. While no specific payload or download URL was extracted, the detection signature suggests it belongs to a known dropper family. Further analysis would be required to identify the exact payload and delivery mechanism.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0