Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3533556f9b9f3651…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 8ed9dc8ebbbc09f4052c65e774e255ca SHA-1: ced92f1de3741ab1178aac0130d7a565eb05463c SHA-256: 3533556f9b9f3651db8f46a8a946f67b48f1837e9c87e7d757fecc3b76b50752
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The document's purpose is to download and execute a second-stage payload, typical of Qbot's infection chain. Further analysis of the document's content and any embedded scripts would be necessary to confirm the exact delivery mechanism and IOCs.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0