Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 287d51cf17b74504…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 81420fd916b78ae7431f038f940db975 SHA-1: 222dfd938a6cb3adeaf0b80df3f0f0dbf8772c48 SHA-256: 287d51cf17b7450422dfffe428d0e8702edf931cf254be89898f13c860861fc7
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its function as a Qbot dropper. This type of malware typically aims to download and execute further malicious payloads on the victim's system, often delivered via phishing attachments.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0