Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1f867b6e01a22975…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 32612ea1f47f69f76ff39366796ab206 SHA-1: db29289ada927a69e47d6d9df76781341622d691 SHA-256: 1f867b6e01a22975615b0347dfd962b246810b8f85002440293bce42d05c477e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper disguised as an Excel spreadsheet. This type of document typically relies on social engineering to trick users into enabling macros, which then download and execute the Qbot malware. The primary attack vector is likely spearphishing attachment.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0