Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 da898c41d811f480…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 6372d4cda8089d1998d36b273fbf6ebe SHA-1: ffd06e8a6482bc78c6347d391b9eb4635943019c SHA-256: da898c41d811f4808f6d3cbb826fc3d9a9546a792abfb228550aa4c7ad0f79c4
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its function as a dropper. As an Excel file, it is highly probable that it relies on macro execution to initiate its malicious activity, likely downloading and executing a secondary payload. The specific family is not definitively identified by the available heuristics.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0