Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 d55f228ef88f6544…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7bb104c5a6364951cd4977e2bcaab45d SHA-1: a8e77dc1d274cbb54f82f9fe0d91de62745cdbbf SHA-256: d55f228ef88f6544572c2e00981651242e652c747c27ecdf5d01a34585a7a527
60 Risk Score

Malware Insights

MITRE ATT&CK
T1204 Malicious File

The file is identified as a malicious Excel document by ClamAV, specifically flagged as a dropper. This suggests its primary purpose is to download and execute a secondary stage payload. Without further script or body content, the exact execution method and payload remain unknown, but the dropper nature is clear.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0