Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c76d467444b39386…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: c7560827ae3172d4a28519142253c724 SHA-1: 18925e7f5b87286f912ebeafd2d3d55969d6ccda SHA-256: c76d467444b39386f1d9783035ab0344fc8c3f453a98b90f092c4db300369886
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating a Qbot family infection. As an Excel document, it likely employs social engineering to trick the user into enabling macros, which then execute to download and run the Qbot malware. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0