Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 42009ad77a4ece62…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9d54c9d7e59bd7505fa97d44220d5e07 SHA-1: f2ead3563b04e1ba0c4edd0e0137e2ccbd06bcd3 SHA-256: 42009ad77a4ece6230d8359e66a19fbfc4e0898c1b34d80a1a5b8d3e4cbcd14c
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0'. This heuristic strongly suggests the document is a dropper, intended to download and execute a secondary malicious payload. Without further script or body content, the exact mechanism and target are unclear, but the dropper nature is evident.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0