Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 9afdef85f262692b…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ba2f3f9d2436d91c5d1c134aaabd8bae SHA-1: a5cd3bd56c017b2e959267d27e66da437be164ce SHA-256: 9afdef85f262692b145c649b74dc2227285d311678a5a5eb56733c0b1e874d2a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot variant designed to deliver a secondary payload. The Office (OOXML) format and the critical heuristic firing suggest this document is intended to exploit macro execution to download and run malware. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0