Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3738e0db8f81d4a1…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7804a2600f95e49aac92b41580046a6c SHA-1: f4ed3b6d0e5522c09ba7bbef214436f5387001c1 SHA-256: 3738e0db8f81d4a1dbfc8eb2acd6b3307bd363c41b06d828b443065e65aa263d
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1105 Ingress Tool Transfer

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot variant. As a dropper, its primary function is to download and execute a secondary payload. The file's structure and heuristic firings support its role as a malicious document, likely delivered via spearphishing.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0