Dridex — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 352767d770508167…

MALICIOUS

Office (OOXML) / .XLSX

128.9 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 15.0300
MD5: 1963a4808a9d94fbc0e380707c150730 SHA-1: bd7a3f1ecef2013b4b45187b728946abcca15567 SHA-256: 352767d770508167e0b3e35ff366d2ccb331ab7ab1bff8dedca0086086bc0f39
60 Risk Score

Malware Insights

Dridex · confidence 95%

MITRE ATT&CK
T1204.002 Malicious File

The file is identified by ClamAV as Xls.Downloader.DridexGreen09211-9890102-0, a known downloader for the Dridex banking trojan. The primary function of this file is to download and execute a secondary payload. While no specific URLs or hashes were extracted, the ClamAV signature strongly indicates its malicious intent and family.

Heuristics 1

  • ClamAV: Xls.Downloader.DridexGreen09211-9890102-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.DridexGreen09211-9890102-0