Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 509ecc535a7999e6…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9cfd3a50a9564849e7f382952359a77a SHA-1: ca4f3778ce823e75e66e388322b54da9b8c8b24f SHA-256: 509ecc535a7999e6202e0a98b17e40ab5cd48449da7844042e606b90b7c4988e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary function is to download and execute a secondary malicious payload. No further IOCs were extracted from the provided evidence.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0