Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 2962e87267d34888…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5572fa022cfebc628f056b366717106f SHA-1: b88b4225f74b16f8f8d4766d015ed8877770dad3 SHA-256: 2962e87267d34888a66d59b1f53116ad4324da2ae28b64e8103e956dbaba0f5e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern is likely spearphishing attachment, aiming to trick users into opening the malicious document. Further analysis would be needed to confirm the exact delivery mechanism and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0