Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 ac83775930cc98c0…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5d8a8b7ee0346734c3c18886cd4f0688 SHA-1: b52b407f79daf003538834192facef692f3f35ac SHA-256: ac83775930cc98c0832122743880b790f94110db5b35eed2a042204d253515b2
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No document body or scripts were extracted, but the heuristic is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0