Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 5967b30393781aa9…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5faee73f0c527da7cf6b016ca7d3abcd SHA-1: f8d6a1c4ac63a205586845327fe56b25a611f909 SHA-256: 5967b30393781aa936ddb73e67efb9525337258df233666b1c94939ed47be598
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. The primary attack pattern involves delivering this malicious payload via a spearphishing attachment. No further IOCs or script details were extracted for this sample.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0