Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 cb1ba89a35c776e9…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ca75a5bd09746fa7732c317c3578837f SHA-1: c1380f9c85a9a1b5143e760e41d0d6b9e653f1b4 SHA-256: cb1ba89a35c776e92057d1eb2071c526e20a539882e1a283faf20ccea7756565
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as a known dropper for the Qbot malware family. While no specific document body or scripts were extracted, the heuristic detection strongly suggests the file's purpose is to download and execute a malicious payload. The presence of Qbot indicators points towards a phishing or social engineering attack vector.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0