Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 34593134ba6ccff1…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b92fe9a6ec70159879d9b08baf48ff76 SHA-1: 659e9a7b31063de63041495b26c55b599cde3511 SHA-256: 34593134ba6ccff1e440a6e1b4f85509d75d05f9b6a4186079b55bd71a620383
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. As an Excel document, it likely uses macro execution or exploits to deliver the Qbot payload. The primary attack pattern involves tricking the user into opening the malicious attachment and enabling macros, leading to the execution of the malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0