Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b96a2f313a2fc3c2…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 84808911f5460854b9aab60dc0b069a3 SHA-1: cb80c5198331f644fbb8a9d4337705c9290b0e0f SHA-256: b96a2f313a2fc3c2a5df05f57854148fdbab15a45f889076e70b030f3863506a
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were extracted for deeper analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0