Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 2be0ce14f66b51b6…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 010d558914d655bd92782ee45da36359 SHA-1: 9844038a38ea874bf827f48b5fa276ef16f9c187 SHA-256: 2be0ce14f66b51b68ee99d85bd6e22be8948bc833e821ef14871b7337b375f90
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1204 Malicious File

The ClamAV heuristic 'Xls.Dropper.QbotDocu12020-9818439-0' strongly suggests this XLSX file is a dropper associated with the Qbot malware family. Its primary function is likely to download and execute a further stage malicious payload onto the victim's system.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0