Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c79c1108c850ac5e…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ac562f87c279ea298b3e251ad6917663 SHA-1: 55d6fc1aaf964472714582119f329bc823ce0263 SHA-256: c79c1108c850ac5e9c3719320172e726f7f54a3e4343a578e5b3359aa564e9bf
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper disguised as an Excel file. This type of document typically uses social engineering to trick the user into enabling macros, which then execute to download and install the Qbot malware. The specific variant suggests a known Qbot distribution method.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0