Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 2671f04c05848a95…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9b219cb2a34abe934a24131eb4bce7e5 SHA-1: dcc5b63768c609f7fa95bdc4a4522b3a5e5c6c55 SHA-256: 2671f04c05848a9556fea7bd302696664ed9e722690735f98131448b05d66b6a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1105 Ingress Tool Transfer

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically uses macros to download and execute the main Qbot payload, fitting the pattern of spearphishing attachments used for initial access. The primary function is to deliver the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0