Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 29425b7ac988b64f…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3fa397bc4aa63e6d82841496e01088fe SHA-1: 4fbc7ae8b12943cfb9d8ad4f0a0e8cc301f37d63 SHA-256: 29425b7ac988b64f5cf25745ac9c3e3efd6046f1b78bc29cb5cacbd7770e7e41
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1204 Malicious File T1566 Phishing

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop and execute a malicious payload. The SHA256 hash is included as a primary IOC. The document's structure and heuristic firing indicate a malicious dropper.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0