Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 444f3572d284a07c…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1ea223777f6e9b50403b701de3b124d9 SHA-1: 58d1a633e6410d722009917f231656baae64f269 SHA-256: 444f3572d284a07ce09837bd5d6fef64661e754f76614b43d8e46303e5fc99f9
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot variant. The primary function appears to be dropping and executing a secondary payload. The SHA256 hash is included as a primary IOC.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0