Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 354203a39993ca34…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0d4427314cd3fc1fbdc181e49bb980ae SHA-1: be259b31561c8b5f04754974e76f3f6be64853a2 SHA-256: 354203a39993ca3493fb5f9fb0b6ea5c623cd62079546e5294e040c5eaf07489
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known for its capabilities in stealing financial information and facilitating further network compromise. The detection suggests the file is designed to execute malicious code upon opening.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0