Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1a2acfb588157dd8…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f0098e2863f6d56c296fff44e5aea509 SHA-1: 660a89a932b81848cf2e3b68ca766127da391a5d SHA-256: 1a2acfb588157dd8cebb2d5f838103f0c5388b96afe42577d8a9a65c8fd42ad3
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop malicious payloads. The detection indicates a common attack pattern involving malicious Office documents used for malware delivery.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0