Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 922fc0c064d110cb…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5489c93ab626c05a8f63fbe13b09cdf4 SHA-1: 62c9376305fb50390001e8b3cda2c8dca546fbba SHA-256: 922fc0c064d110cbc86d2544cabe114209184dec0b1a1027e5114d38657ae359
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0