Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 58b9b308ff067099…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 4cc63c679a4d9d8b1c3cf5debf908ce7 SHA-1: 04453292639559b3d4b34ba5f7cc9b7af1647a00 SHA-256: 58b9b308ff06709950495235932a488e8ffd5e5c7697d21bc9855d4d4a7bc188
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1204 Malicious File T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically relies on social engineering to trick the user into enabling macros, which then execute the malicious payload. The primary function is to download and run the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0