Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 b7b49477e2c9b2bc…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9cb4be0202c8bb5116ef6d318340a1de SHA-1: 28417fe547e1a58c538e13e8eab0324f9d98aee3 SHA-256: b7b49477e2c9b2bceb0d3f4b1c9645c0cde7cc6f144b936fe11022e4d6e55c40
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0'. This heuristic strongly suggests the document is a dropper, intended to download and execute a malicious payload. Without further script or body content, the exact nature of the payload and delivery mechanism remains unclear, leading to an unknown family classification.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0