Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 c72645e12bfa0550…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d641269df14b947a9b32cc3718746607 SHA-1: 2b26aa8ac560fc39920a78593779d771106d801b SHA-256: c72645e12bfa0550fcd446d097caa7804e6f433716f69aebac594b5f45001b38
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as a malicious Excel document. The CLAMAV_DETECTION heuristic specifically flags it as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper for other malware. Without further script or body content, the exact payload and delivery mechanism remain unknown, but the intent is clearly malicious.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0