Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 9a8cd328e2bfdbd5…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 03fbbe32868dd1bc60465946445fb60e SHA-1: 7a4684b5c67aaf37ea8eaa1f7c1760f2d1ae6359 SHA-256: 9a8cd328e2bfdbd52f329488721232f07eaa9faf832b862525dc58962ace21d9
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel spreadsheet with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. Further analysis would be required to identify specific delivery URLs or payloads.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0