Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 282e71c66ec8dfcd…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f2fc33f6d250238ef3014593fb5490c7 SHA-1: 590dbf1e6717a46f8cd21a862195d4744cddab16 SHA-256: 282e71c66ec8dfcdb63824ae441e3c7c9b2e918e60d01a1b9d04a445bea7697d
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This dropper likely facilitates the download and execution of the main Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0