Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8ec7dce15cb264b3…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 80f207adb0944e1c254eb63c2ffef6c5 SHA-1: 43074f00dbc35b02ee0df531261fab596ea979d3 SHA-256: 8ec7dce15cb264b3539f3b22b6d219ce2fe6f4cc021459f476cf75cc12d3508c
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0