Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b4a137af39fed42b…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 42c8dc581f6a2100b50f395eb2fbbded SHA-1: 4ce0543ebe167b03715be0c64046e2b78581ad29 SHA-256: b4a137af39fed42b6be75bff38038890d355a113ed028775c45e6251d121fc2a
60 Risk Score

Malware Insights

Qbot · confidence 85%

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting a Qbot family infection. The primary attack pattern involves a macro-enabled document designed to download and execute a secondary payload, a common Qbot distribution method. No specific IOCs were extracted beyond the ClamAV signature.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0