Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 5406244fab2aaea9…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 819ad1ea943d3f5eb714cebdeb3d1a20 SHA-1: 18b892d11e1896aa42c8a270f09356d2afc8cfde SHA-256: 5406244fab2aaea9036c1f4e272e06cecdff908ac210bd2b5034b1cfafa982ab
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0