Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 f1a1ac3af9cf053c…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3d9622fee58bd7ddd7decd7ddc24286d SHA-1: 0d4a690e1f6a5c313de0996987a2c5072baf7642 SHA-256: f1a1ac3af9cf053c9c746c946ee204e327f11b490f6ea6249c4e1cabe955d615
60 Risk Score

Malware Insights

The file is an Excel spreadsheet identified by ClamAV as a dropper. The heuristic firing indicates it is likely designed to execute malicious code, potentially by leveraging VBA macros to download and run a secondary payload. Without further script or body content, the exact mechanism remains inferred.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0