Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3b73942bd36dd712…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2d96d2af20a6a5ff4092a8436a71927d SHA-1: ba112d3db84c7e67765bf7e4ed3e56a8fc4d8f77 SHA-256: 3b73942bd36dd712ab99f46084d5f90887d3f19bd6f12275a65798fdf8f6e566
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The file's metadata and heuristic firings strongly suggest it is part of a Qbot distribution campaign, likely delivered via spearphishing.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0