Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 e4e27c7230d230a8…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0aff5bc686f43f354eccec8073b917e3 SHA-1: 08458d24a0e0b5e683f8a6a60d6583805ca0d1d5 SHA-256: e4e27c7230d230a84a36c6e7d0c49e9683259d18c4d0c693175818496d0f8f50
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified as a malicious Excel document by ClamAV with the signature 'Xls.Dropper.QbotDocu12020-9818439-0'. This signature suggests the file's primary function is to act as a dropper for other malware. No document body or scripts were extracted, but the heuristic strongly indicates a malicious intent to deliver a payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0