Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b1a1ecfd71a692b5…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 35910dd6bd8bf79996b5ab3093a3df49 SHA-1: 3fbce276acf79c5cc48207ef6d8fbab210ca86d2 SHA-256: b1a1ecfd71a692b5429ae5e5329d2a868f4fde2ec63dc96a7005dd58b82edfef
60 Risk Score

Malware Insights

Qbot · confidence 95%

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant. The primary attack pattern involves tricking the user into enabling macros to initiate a download and execution chain. While no specific URLs or scripts were extracted, the heuristic detection and file type indicate a dropper functionality.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0