Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 31265abd6d2f9cf4…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2579dd2a3697548a6870981c56d1d64a SHA-1: 0cff7c50ba36448b2624e4e2a3fff0bbffbed58b SHA-256: 31265abd6d2f9cf476c79f68e46f0106cc1592ab894e4341e29e86755cbe35ac
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop a malicious payload. The primary attack vector is likely spearphishing, relying on the user to enable macros to initiate the infection chain. No document body or scripts were extracted, but the ClamAV signature is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0