Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 209a1d76a5580349…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5f5d8a73b8b188175f06f31599ec6e0d SHA-1: 0d0d82b3f27699fc4dad1950272decf0d977d360 SHA-256: 209a1d76a5580349446fbd91a7b4237f6b179bfc681eaf059467a22313685e8a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically relies on social engineering to trick the user into enabling macros, which then execute the malicious payload. The primary function is to download and run the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0