Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 9a81f4783f2a9993…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2dbe259858694bcd7f242222ab154181 SHA-1: d4e7e73241f9ed3c279267eaa2cd09bc1e472298 SHA-256: 9a81f4783f2a9993f191f6e0130c6142bcec8e631e5a3c117effa9c71a2e2de3
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial infection vector for the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0