Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 520b1d8eeba62bab…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 706e9f44559be3b49549bd70f823b75c SHA-1: d42f47a6ef6ba97977fc156f4557391017c5131d SHA-256: 520b1d8eeba62bab4fbcf1615ba46e5892f1c40514695d669834b0be0129e90a
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Such documents typically employ social engineering to trick users into enabling macros, which then execute to download and install the Qbot malware. No further IOCs were extracted from this sample.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0