Dridex — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8b92dff85e5903f2…

MALICIOUS

Office (OOXML) / .XLSX

124.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 15.0300
MD5: fb2959ee19ff1022fae8e98c9d7ec045 SHA-1: 02622e2bf66de8749380c2d275d37ab9fa5e3c6e SHA-256: 8b92dff85e5903f2ccdeaa93e9714b98445fa631d08b7dd8428cdb15d3f8542a
60 Risk Score

Malware Insights

Dridex · confidence 95%

MITRE ATT&CK
T1204.002 Malicious File

The file was detected by ClamAV as Xls.Downloader.DridexGreen09211-9890102-0, indicating it is a Dridex downloader. The primary function of this file is to lure the user into opening it and then download and execute a secondary malicious payload. No further IOCs were extracted from this sample.

Heuristics 1

  • ClamAV: Xls.Downloader.DridexGreen09211-9890102-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.DridexGreen09211-9890102-0