Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 3e94f3b90d015218…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 8f52ccfea6ca60947c95a1d5833f5236 SHA-1: 7d88614ad64ed8e615833c348e2cde905600f621 SHA-256: 3e94f3b90d015218d652571908b753238c617523c25d5e7c33dbec35da566707
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot variant designed to deliver a malicious payload. The primary attack pattern involves luring the user into opening the malicious document, which then executes the embedded malware. No VBA or scripts were extracted, but the ClamAV signature is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0