Malicious Office (OOXML) / .XLSX — malware analysis report

Static analysis result for SHA-256 fdc21a067ab604d2…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 32a69e0747a1fc6c29e9aacb9825a0ff SHA-1: 17e061e40a0d1cfa42ee058c3c6ecb3039a2f577 SHA-256: fdc21a067ab604d23fb8865dbf51662f5b702dea0e8e5c0fca9df0d121186968
60 Risk Score

Malware Insights

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is an Excel document with a ClamAV detection signature indicating it is a dropper. This suggests the primary function of the document is to download and execute a malicious payload. Without further script or body content, the specific payload and delivery mechanism remain unknown.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0