Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 7d72df4d09d416b2…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 167dd6afdda53465630d93cd3fb6fef3 SHA-1: 04a0a8ee9b6517eb725869a2db62490cf4e4ebee SHA-256: 7d72df4d09d416b2a4045cfdba204161eb883a5fc36c82645e5703b1ecdc02b0
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper. The primary attack pattern is likely to trick the user into enabling macros, which would then download and execute a secondary payload. No specific family could be confidently identified beyond its dropper functionality.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0