Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a2567c3479335c1a…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 20df383eafa4b8680ce73e61a61b632b SHA-1: 65835f6c12a1e2cb0ff46aa48471141414adca5c SHA-256: a2567c3479335c1acbbc1a13257485e2ce33818fb485924a5e167de2a5bdfbfd
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: User Execution

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. As an Excel document, it likely relies on social engineering to trick the user into enabling macros, which would then execute the Qbot payload. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0