Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 20349dcc7c26cabb…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: facb3e51ce7984dd1fcd02527ce14957 SHA-1: 4ce24309c0807fe5e9430bd01525b245e7f38a29 SHA-256: 20349dcc7c26cabb853176853a1c690b3e1a344f3c4ae383d4413b9a40f25cf8
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a Qbot dropper. This type of malicious document typically relies on social engineering to trick users into enabling macros, which then execute to download and run the Qbot malware. The primary attack vector is likely spearphishing attachment.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0