Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 997e20c301a74847…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 319721f5a46fc8c3a6d9c6f28d8a7f04 SHA-1: f7abe019eddcc14bfc0024d6694f0eb588e97fc3 SHA-256: 997e20c301a74847c8c9b3658a2870b7e3d167cb4f663a469715a539bdf22901
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot dropper. This type of document typically relies on social engineering to trick users into enabling macros, which then execute the malicious payload. The primary attack vector is likely spearphishing, leading to user execution of the embedded malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0