Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b19244b45714578e…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5e37cc69aeb28d5bb8551fdd774a7c28 SHA-1: 0ceafe5eec7f22378d4ea2db7fc58d0302a36b14 SHA-256: b19244b45714578e1a9af665fb9b23ddb45277283e2153e48d25f60373c63de3
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File Execution T1566 Phishing

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper for other malware. The presence of macro-related heuristics suggests it likely attempts to execute malicious code upon opening, leading to the download of a further stage payload. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0