Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 bf4ccb058c96de6d…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 290ffb9b95d0ca2fa9495638d0050582 SHA-1: 5d89ee2bfb8531c845a8a99c453c1e206b1b18f8 SHA-256: bf4ccb058c96de6d931ff57a1d92bb62071cf369045c8ccea441f052e78a0727
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0