Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 bf7a2a339c99beea…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 907a83b441267fe941b95bb45fcd7500 SHA-1: 095f7ff6043538b705f505b7bcb92089534c2d48 SHA-256: bf7a2a339c99beea73dde2f503f843185cea869eac39b89184484183b2bebec8
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically uses social engineering to trick the user into enabling macros, which then download and execute the Qbot malware. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0