Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1ed344a54badf4d7…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 587ed8f52cf63851f5c9720222fc30ac SHA-1: 6a0c1e142b40ff500e9aa76f7931b3eb6369d489 SHA-256: 1ed344a54badf4d74030a0efce923811cb1a8105434a6ccab9fac65366af4d85
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its role as a Qbot dropper. This type of malware typically aims to download and execute further malicious stages onto the victim's system. The primary function is to facilitate the initial infection vector for Qbot.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0