Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f08a8bc18c76d82a…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b680b25e38e6cd64dc5b33c1a4b7e354 SHA-1: 3f544103d7304fc8f15a5e2c22623e98057ba126 SHA-256: f08a8bc18c76d82aedbd853066a74780278bb4f87e54f6edd7ec9a232c2db104
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as a known dropper for the Qbot malware family. Its primary function is to deliver and execute a malicious payload. The detection signature indicates a high likelihood of this file being part of a broader malware distribution campaign.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0