Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 37e7549582f32275…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ccf632bdd0b94b2a80342b31824dfe15 SHA-1: 900c16e67f7bcd98f6c7f655d5202d7aa2ba698d SHA-256: 37e7549582f32275e43382e0bf2c81675c8c416a54af00b92940eebfc3eedea0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as a dropper. The presence of macro-related heuristics suggests it is designed to trick the user into enabling macros to execute a malicious payload. Without further script analysis, the exact nature of the payload remains unknown, but the detection name implies a Qbot variant.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0