Dridex — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fc23327d65cd6c5e…

MALICIOUS

Office (OOXML) / .XLSX

128.9 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 15.0300
MD5: 4d2beb22bd01cb81f7be7ce98752bf2a SHA-1: 9c50f9b98a945e73c59b1faab2fdd84719e0a448 SHA-256: fc23327d65cd6c5e2811f0d3bcc96e6d2d322e5cb05645fb13df9def599dab38
60 Risk Score

Malware Insights

Dridex · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file was detected by ClamAV as 'Xls.Downloader.DridexGreen09211-9890102-0', strongly indicating it functions as a downloader for the Dridex banking trojan. The primary attack pattern involves luring a user into opening a malicious Excel file, which then executes to download and install additional malicious software.

Heuristics 1

  • ClamAV: Xls.Downloader.DridexGreen09211-9890102-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.DridexGreen09211-9890102-0