Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1ae16a663cd8d2db…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 806a03b39ab17a393b8e47b39b7f96cf SHA-1: f747386b632859f68262dfa4d9d528ea0136ed3e SHA-256: 1ae16a663cd8d2db4e8f8972c736233b785e39ac11be20a52fae9bf4d9869070
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The ClamAV heuristic 'Xls.Dropper.QbotDocu12020-9818439-0' strongly indicates this Excel file is a dropper for the Qbot malware family. Qbot is known for its capabilities in banking fraud and information theft, often delivered via malicious Office documents.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0