Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a462e00e795cdced…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 400c62257e887f11aff9258f0d1f0bdb SHA-1: 610814553a9b41058c11ce9234587d0bd7fb7515 SHA-256: a462e00e795cdced97b07c5df0008de40df8d1d85b4c3fc88fe189655d543f5a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The critical ClamAV heuristic firing, 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicates this XLSX file is a Qbot dropper. Qbot droppers are typically used to download and execute further stages of malware. The SHA256 hash is included as a primary indicator of compromise.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0