Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a6193ffb8928d07d…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2f7dae331437e6b26cd46591a25d3404 SHA-1: 0600ff34891e75a3d29c26734e89e9b915708605 SHA-256: a6193ffb8928d07dc9440d26b351361ab437f81fda5414a6097eff22e3fb8e47
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. As an Excel document, it likely uses macros or other embedded content to initiate the malicious payload. The primary function is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0