Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 90e347309db705c7…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 955710103ed8838b891b8eec97e5da27 SHA-1: 60bc7fbe796c170ed1481d91f498dc6313566196 SHA-256: 90e347309db705c76cf1feb4e35f2fc1669be1f4e00c642c39336977be4241bd
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial stage for downloading and executing the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0