Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 84b32ffd6ccc4291…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 26ec1f6b86ab9050ead18d818033db15 SHA-1: e3b3ce74072482942df0944fb0cde83ef45acc9a SHA-256: 84b32ffd6ccc42915507ea3c3f2059b07905536b12e39b7bb3d0fb825d83f73e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as a Qbot dropper. The heuristic firing indicates a high likelihood of malicious intent, specifically to drop and execute a secondary payload. While no document body or scripts were provided, the detection signature strongly suggests a phishing or social engineering attack vector, likely involving macro execution to initiate the infection chain.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0