Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 7c2e47324199fc72…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3a07b70276cf618ca676f4b63cb55414 SHA-1: 584ea0e041ffeee7a56c3908f794ba1fa9fcfbbc SHA-256: 7c2e47324199fc720932d63a289fbe822abfbdd9a8c157bdedba9f4b522eaaa8
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File

The file was detected by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper for other malware. While no specific scripts or document body content were provided for analysis, the heuristic strongly suggests the Excel file's primary purpose is to facilitate the download and execution of a malicious payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0