Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3700a1735c2554ff…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: a39be2f2049bdd02d8f5c6059778ff9b SHA-1: 70e06e8a0148fe0f6cca3c19be83656e6ab4096d SHA-256: 3700a1735c2554fff18a2099558a9ac51e36d83033425901b58a46eb96118f59
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to act as a dropper. As an Excel document, it likely employs social engineering or exploits to trick the user into enabling macros, which then execute the malicious payload. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0