Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 aff6a58211e88bd7…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: f43283f269ab15c6be631f13f790ca11 SHA-1: aadd7b9cb7828044676bd41e09c278ced5994df0 SHA-256: aff6a58211e88bd7d3e643febdefa43062bb6547ff7139b49a6cf55631105d63
60 Risk Score

Malware Insights

Qbot · confidence 95%

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it's a Qbot variant designed to drop a malicious payload. The detection name itself suggests a dropper functionality within an Excel document. No further scripts or document body content were available for analysis, but the ClamAV signature is highly indicative of Qbot's typical behavior.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0