Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b7509f14d6d8d7ad…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1b5411b6c62ff3654aad86496b45d14a SHA-1: 3cd2da8c02317ca5cb1a831efcc996f7a1887869 SHA-256: b7509f14d6d8d7adb45a2eb4f1b6bce7e636ca79612745dd3627f8b3b8d5defc
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot variant. As an Excel dropper, its primary function is to execute malicious code, likely a secondary payload, upon opening. The presence of macro-related heuristics further supports this attack pattern.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0