Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 bdd19f53c9d248e8…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 9c9f23def68e7f71afc348a0466f4fc3 SHA-1: 6d4a82d9f75c5a2946a2d300600d0c6bd02b4024 SHA-256: bdd19f53c9d248e843c7084bc1ad8eb03a779e60dc104f672c36b1f036065994
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as Xls.Dropper.QbotDocu12020. This heuristic strongly suggests the file is a Qbot variant designed to deliver a malicious payload. The primary IOC is the file's SHA256 hash, indicating its role as a dropper.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0