Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3ba33739aa4029b2…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0879b61c4cdfa11c08d3e707f1f6c7b0 SHA-1: cb8d616d394c6cd4d3fd81c7024310a7d3d481e4 SHA-256: 3ba33739aa4029b216f3fbaf0241c201feff1c1ff8468c28ff10b6539cdcf842
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of malicious document typically relies on social engineering to trick users into enabling macros, which then execute the malicious payload. The primary function is to download and execute a secondary stage, consistent with Qbot's known behavior.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0