Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a99913585fe1cfe4…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 92bfadd334f080b5f4e0f106e61c00d4 SHA-1: badd60ab95432bc39bc59451f91fb217f037945f SHA-256: a99913585fe1cfe4a08e3eedb47bd8af321fdf3b09a0764bd49a949feed20775
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0