Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 95c11aaad2d558a2…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9379cf6b07a15f1004b15441b96fca24 SHA-1: c1b12c74a46e379db24db3d8788daee486b2e7a3 SHA-256: 95c11aaad2d558a2f37632ecd5242a3af57231cc330546879a3cf5cf286751f8
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of malware typically uses malicious Office documents to lure users into enabling macros, which then download and execute the main Qbot payload. The primary attack vector is likely spearphishing, leading to user execution of the malicious macro.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0