Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a0f56a62acec36cc…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f09d99d862c36e387388e72611c16bb4 SHA-1: 80cc85b86f0652ea575f2c1e9f817d48dbd2ed4a SHA-256: a0f56a62acec36cc516411bd0aaea3c2f248af8cf3a1e61232d57befac75729e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop further malicious payloads. As an Excel document, it likely uses social engineering or exploits to trick the user into enabling macros, which then execute the malicious code.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0