Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3b6ab75f46e5e4f6…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f4c1cd1895a028d8d1b527215d4b5b75 SHA-1: 7ea96ac4b90d87204cb7506d046c39ff0e78b81f SHA-256: 3b6ab75f46e5e4f64c69b59cd0b9d37ec92fe706981cec3cc5a13b911ae40eaa
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. This type of document typically relies on social engineering to trick the user into enabling macros, which then execute malicious code. The primary function is to download and execute a second-stage Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0