Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c663844288c481c0…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ef30f5d0ea751c92750e75a73a1e1ffa SHA-1: 854e1102b965446881c5ffdedc483b7066a91f1c SHA-256: c663844288c481c00b52d05e1c44a72e5faf8425d2c909522d010acdeecf3c43
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as a malicious Excel document. The CLAMAV_DETECTION heuristic specifically flags it as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The document's purpose is to download and execute a second-stage Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0