Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 9c513af89acb9b81…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 72e30a5a94e6fb6c649133794dc9d092 SHA-1: 3036cb801141e841891cb27ad783fd4e2f037294 SHA-256: 9c513af89acb9b8104d70cf33f0fd44b3a5097e5b507a8c6d6fdc1d086435be1
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, indicating it functions as a dropper. Dropper malware typically facilitates the download and execution of additional malicious payloads. The file's nature as an Office document suggests a phishing or social engineering vector to trick users into enabling macros, which would then initiate the payload delivery.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0