Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 4d2c03c805225b29…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0149668652d931d667cc75e2d2ffe696 SHA-1: ca04f2c7d3acb98bea96a37fe71da86d182a60c7 SHA-256: 4d2c03c805225b299c877e91a3298e0c318b9f0ca477fde22f6536d89465f8cc
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic explicitly identifies this file as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its role as a Qbot downloader. As an XLSX file, it likely uses macro or other embedded content to initiate the download of a Qbot payload. The specific nature of the payload delivery is not detailed by the heuristic alone.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0