Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8af89c06d057f1dd…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f742757f2e6a8180b974328be4dcdf97 SHA-1: 65f4874de29789dd98101c7b537b4830123fe7e1 SHA-256: 8af89c06d057f1ddb1ec1507ea736734c10b2cf6a7ff13ea4cf885290099b072
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot dropper. This type of document typically uses malicious macros to download and execute the main Qbot payload. The heuristic firing directly points to its function as a dropper for the Qbot family.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0