Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 8f7c33fc03aa2eea…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7e80ada5c4cc61f111f80203dd3ceef9 SHA-1: 0687427873dc4432f0efa5b736a89e7eb0a3cab6 SHA-256: 8f7c33fc03aa2eeabfa1ca96b2dc0d053c148157c40d4fc301611c90515acc98
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot dropper. The primary attack pattern is likely spearphishing attachment, where the user is tricked into opening the malicious Excel file. The file's purpose is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0