Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 49a73f001c5cafb5…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 454d6436b0e5208b250d6d12d8b538c3 SHA-1: ddeff50ed5dbb16d132c2de1c2ab8f31220a6b93 SHA-256: 49a73f001c5cafb5f4586cbf27e5cbc040dda3a09034c6d3b208a97d11a32bc1
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. The primary function is to deliver a malicious payload to the victim's system. The SHA256 hash is provided as a key indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0