Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 40608fb2ae42c958…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0eb8796ad0a8300b53dec3d008b83c4d SHA-1: 70386fc64cca1cdbbe62eb305c753ce6ccf343e6 SHA-256: 40608fb2ae42c95851b53a32655089e29c53a37628e38b4f922620fac7f5c189
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically uses malicious macros to download and execute the main Qbot payload. The heuristic firing directly points to the malware family and its dropper functionality.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0