Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 4f0a6ca4363a3892…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 4ae9e824d3474e658cb85c7b1a182862 SHA-1: 78a92be36e4463ed879fc312c4339b9df04ea27e SHA-256: 4f0a6ca4363a38925b0dacca24082219d4e67aec04ee580516647abb3be4dc46
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is an Excel document identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. This type of file is typically used to lure users into enabling macros, which then download and execute the Qbot malware. Further analysis would be required to identify specific IOCs.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0