Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b14d45fdaf6b58ff…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5b632d1a6612212cf1e20aed499dc6f1 SHA-1: a0a5f91a2f5be9b3b12802ccfbcb99b67e9a6f09 SHA-256: b14d45fdaf6b58ffad6b0766523af0293fca257af3af64d8dcfc7917e4524655
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were extracted for detailed analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0