Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3885449d356f6514…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1e470dcff0b1c99d0ffb74205e2efd0a SHA-1: 751b872b03e983e9f526c2878f051189e5b7ec7c SHA-256: 3885449d356f6514603c96e2dbd782cf5a59f4b1ffed92ccb6076267d912406d
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The heuristic firing suggests the document's primary purpose is to deliver and execute the Qbot malware. No document body or scripts were extracted, but the ClamAV signature is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0