Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 594cd1abef732bd4…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 82b8ba769b021ff44ddf3c89822a135d SHA-1: 2524c791d610514c8fede520bc7c7053b336a814 SHA-256: 594cd1abef732bd4db6013aa05eb118aeea64903a569f39de6941163457a09e2
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of malware typically uses malicious Office documents to trick users into enabling macros, which then download and execute the main payload. The primary attack vector is likely spearphishing attachment.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0