Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 93f3c6ca11374772…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d7ebc0f1ef148fa1b6aa38e25bb87d04 SHA-1: dc844b7976dae38c64f4afdd9f92882ac719e46f SHA-256: 93f3c6ca113747728411ff32e0682bcb7d9d3114f7af7e246f27a29aff1ede35
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot malware family. The presence of macro-related heuristics suggests it likely uses VBA to download and execute a secondary payload, a common tactic for Qbot. The file's nature as an Excel document points towards a spearphishing attachment delivery method.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0