Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 903dfc9f9c0f7444…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3964efe3e2ad1d6832c30a30fa692b8f SHA-1: 42b9c035f75b210169e647d9b41af9d9b1066897 SHA-256: 903dfc9f9c0f74446c139b35b2fbc36720f6a64a069ad7258d7d689597ad349b
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File

The file was detected by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper. This suggests the primary purpose of the Excel file is to download and execute a malicious payload. No further IOCs or script details were extracted to refine the analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0