Malicious Office (OLE) / .XLSX — malware analysis report

Static analysis result for SHA-256 89e3a51fcc764dd0…

MALICIOUS

Office (OLE) / .XLSX

804.5 KB
MD5: 44bc4b39af95a17a4ee028d1c13cbbe1 SHA-1: 7acc3b683b97172e6d3f7061d5c309750462078c SHA-256: 89e3a51fcc764dd00ac167656a7b91bb8f8f310ab9d72ec26d2c6d5bb97dd449
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204.002 Malicious File

Static analysis identified the file as an encrypted Office document. ClamAV detected it as 'Doc.Dropper.Agent-7860002-0', indicating its function as a dropper. No document body or scripts were extractable due to encryption, limiting further analysis of its specific delivery or execution methods. The embedded URL heuristic suggests it likely attempts to fetch additional malicious content.

Heuristics 1

  • ClamAV: Doc.Dropper.Agent-7860002-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Doc.Dropper.Agent-7860002-0