Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d007bdfafef7fb51…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 90843ba48f033f6ffeba017b05bfada7 SHA-1: f880a6516b801cd2ec6dea0b754c4e3b7128e926 SHA-256: d007bdfafef7fb51396d6d7e6da367008bfecdfd418dcffa9f86487e7067e9ee
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as a known dropper variant, suggesting its primary purpose is to download and execute additional malicious content. While no specific scripts or document body content were extracted, the heuristic detection strongly indicates a malicious intent to deliver a second-stage payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0