Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 aeebdbb09192ae73…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 368d54e0ce55cacb86b9ffed87c9da0f SHA-1: 0e8fb4000c50f9589c684af86794b68a38df372a SHA-256: aeebdbb09192ae734a2f4c98dcfe6b364a4d27dd9230f1c7932192d6c5bf9447
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial infection vector.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0