Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 43bc0ba3af76f251…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3930df4d9d3b0105b54ed87e84599589 SHA-1: e18c2974ffa5b80c4f815f1763b25ad721a1128d SHA-256: 43bc0ba3af76f2513ccefb73cd86a5a0d0a0fab6da3c3d525c7177c89c9291ab
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, indicating it functions as a dropper for other malware. While no specific malicious scripts or URLs were extracted, its nature as a dropper suggests it is designed to download and execute a second-stage payload. The file's metadata indicates it was created in 2006, but the detection signature is recent, suggesting a re-emergence or updated variant.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0