Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 979ed56c6e401e50…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1e857df7718d1ca904b88399dd80e17b SHA-1: 979d76dea9b6cf9523a67decb35589421efef653 SHA-256: 979ed56c6e401e50fe46729734f17fa777d5c3a973e8f769c2fa91fe23b476bf
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The critical ClamAV heuristic identifies this XLSX file as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically uses social engineering to trick users into enabling macros, which then download and execute the Qbot malware. The file's metadata shows it was authored by Microsoft Excel 14.0300, a common version for macro-enabled documents.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0