Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 493233913f3277e2…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 8b7ccc12d9a45372417ed063dbb0bbfb SHA-1: b5aa575b70eeee46dd81e0dca625098a450cf694 SHA-256: 493233913f3277e2df825a353f2005f146dfbd8f23230ba188d24a9d07f1f6e9
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The detection name suggests it is an Excel document designed to drop the Qbot malware. No document body or scripts were extracted, but the heuristic firing is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0