Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 7fbc8d7a9dd8e180…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 23ffb8f94e6f5928a8c33850d7c39de2 SHA-1: 9c40612fdc906495a1989762251d38a8460b37b5 SHA-256: 7fbc8d7a9dd8e1802d7bd3e9920de4ca82e76ee6d5f1ddf10dfeb54fc81f476c
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. As an Excel document, it was likely delivered via spearphishing, intending to trick the user into enabling macros or interacting with malicious content to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0