Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 ad13b679df5e7590…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 8b4a5bf576d4a1c2b9ac5bd6dbeb2fe7 SHA-1: fdc168a38b03c8bd9c29ce437fc04dbf46e44872 SHA-256: ad13b679df5e7590911954e460f0f0e40b61f18cbdbf8e45af5f7533a8c01c4e
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File Execution

The file is an Excel document flagged by ClamAV as a known dropper variant (Xls.Dropper.QbotDocu12020-9818439-0). This indicates it is designed to download and execute a secondary payload. No further details on the payload or specific IOCs were extracted from this sample.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0