Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1f54d6883d9a19bf…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 4e5334f5bbc6e7cef2373370d96091cc SHA-1: 250e5fbd2c632dd395b29203c37d669cac52e33a SHA-256: 1f54d6883d9a19bfad410f6f215679ea90c8df85a5a23108adcae6d419bbaff4
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern is likely spearphishing attachment, where the user is tricked into opening the malicious Excel file. The file's purpose is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0