Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8cff8f50d80e1a31…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 66ec605d7fafbfe43e52ac5e81b8dbf7 SHA-1: 66396bc36954667d968a24340999e0542cbcf123 SHA-256: 8cff8f50d80e1a3149bee2b75350cff22ac5aec9fb2d1bbf782fad63c2c3f69a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using macros to download and execute the main payload. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0