Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 97127df4e34fcf77…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: e66ff5805d45f1a36c98dc9513450091 SHA-1: cd6c6ef9c2f7cec70485ca40958a864a660a95f0 SHA-256: 97127df4e34fcf775bbe090f2d641f741300474449fd96b23beeefbce9d1615e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern is likely spearphishing attachment, aiming to deliver the Qbot malware to the victim's system. Further analysis of the document's content and any embedded scripts would be necessary to confirm the exact delivery mechanism and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0