Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 4a3430a2b6f9604f…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: c01f40cc4ead8c14940a3d6fa525161d SHA-1: 7aeddf6d803cb2032f139419b87f0781ef005dcc SHA-256: 4a3430a2b6f9604f35399dc06b7b0bb53219743d9535a68f3a5c11921b7dde32
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it functions as a dropper for the Qbot malware family. As an Excel file, it likely relies on social engineering or macro execution to deliver its payload. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0