Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 7f379406992ee4fe…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5a645bfcad7e443c9f5c79371aab1051 SHA-1: 172c52eea7d5904b5bb07340bc7f1c589b8351ee SHA-256: 7f379406992ee4fe86f6be849b0fda0d47924ea2ee7742766db1250cca60d01e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1204 Malicious File T1566 Phishing

The file was detected by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot-related dropper. Dropper malware typically aims to download and execute additional malicious payloads onto the victim's system. The primary function is to facilitate the initial infection stage.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0