Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 2345bd847bc2616d…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d4f9788e3d7596cd447c0bf5586596d9 SHA-1: bb3906c7f2a96f86e3f85009f2452826ca71d672 SHA-256: 2345bd847bc2616d927ae69a9af2c32fa3f2709e9f34a796e8a03ab39b9bb00e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot dropper. The detection name suggests the primary function is to drop and execute the Qbot malware. Further analysis would be required to determine the exact delivery vector and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0