Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 ae826e7e4b43b3c0…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9700f0d90935cd31096028d7cd4da95c SHA-1: 843aeb20f3e88515f7c3eaa45d8b1f817661b18b SHA-256: ae826e7e4b43b3c09c1dd258e616e1fe4cc1d515b133cf4161bfad783e45a364
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as a malicious Excel spreadsheet. The critical ClamAV heuristic specifically names it as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot dropper. The file's purpose is to deliver and execute a secondary malicious payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0