Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 8b121190499ddd73…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7dad2e0184d9b8caf3d546a301158848 SHA-1: 26cf266518751533ee8134af73c3b658018e9596 SHA-256: 8b121190499ddd7385d4b07c8716b26a40966c8900eb1885e91fa6cb300ca526
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File Execution

The file is identified as a malicious Excel document by ClamAV with a critical heuristic firing. The detection name 'Xls.Dropper.QbotDocu12020-9818439-0' suggests it functions as a dropper, indicating its primary purpose is to download and execute a secondary stage payload. No further details on the payload or specific execution methods were extracted.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0