Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b15139653abd90fc…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 269f0d7e0122feac94fa25aa87508798 SHA-1: ed5721bee7ba0114c3a14f23fb572da406d617ce SHA-256: b15139653abd90fcb78827ec98454d14872e50711faa16c45124f70dae1a071f
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. The primary function is to deliver and execute the Qbot malware payload. Further analysis of the document's content and any embedded scripts would be necessary to determine the exact delivery mechanism.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0