Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 861728555fea08b7…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f345f4a298514807adb793fd75981855 SHA-1: 0043d627caf0260cd3bed5a2a15876225735f504 SHA-256: 861728555fea08b771eb6334e83ebd9d080d944d4bb61f4e0626337d3618160f
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot malware family. The spreadsheet format suggests it was likely delivered via spearphishing, intended to trick the user into enabling macros or otherwise executing the embedded malicious content. The primary function is to download and execute a secondary payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0