Xls.Downloader.Agent08210-9888570-0 — Office (OOXML) malware analysis

Static analysis result for SHA-256 54df7d151706bec3…

MALICIOUS

Office (OOXML)

251.1 KB Created: 2021-06-07 17:47:41 UTC Authoring application: Microsoft Excel 16.0300
MD5: 5d76ccdb82b9258f6b54ffc6408bdd0d SHA-1: 864bcd3d508a6b16c31b614c90e0f8e064f90586 SHA-256: 54df7d151706bec375ee1a596e99d1c0c4d15945142afa0e0b012aa096b6d350
98 Risk Score

Malware Insights

Xls.Downloader.Agent08210-9888570-0 · confidence 95%

MITRE ATT&CK
T1566.001 Spearphishing Attachment

The critical ClamAV heuristic identifies the file as Xls.Downloader.Agent08210-9888570-0, a known downloader. The presence of a fake invoice lure and an external hyperlink further supports this, suggesting the document is designed to trick the user into navigating to the provided URL. This URL is likely used to download and execute a secondary malicious payload.

Heuristics 5

  • ClamAV: Xls.Downloader.Agent08210-9888570-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Agent08210-9888570-0
  • External relationship medium OOXML_EXTERNAL_REL
    External target in xl/pivotCache/_rels/pivotCacheDefinition1.xml.rels: /Users/goods/Downloads/JMS ENGINEERED PLASTICS INC_SOA_June.xlsx
  • External hyperlinks (1) low OOXML_EXTERNAL_HYPERLINKS
    Document contains 1 external hyperlink — clickable URLs are stored as external relationships. First target: https://app.mockplus.com/run/rp/DzwNqsd-gpbP/q3X2lMjR1tXg/im9t1xNwMXF?ps=0&ha=0&la=0&fc=0&out=0
  • Fake invoice / payment lure low SE_INVOICE_LURE
    Document contains invoice or payment language paired with an action verb — useful context when combined with link, macro, or attachment indicators
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://app.mockplus.com/run/rp/DzwNqsd-gpbP/q3X2lMjR1tXg/im9t1xNwMXF?ps=0&ha=0&la=0&fc=0&out=0