Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c8ce26280fe7556c…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 31f9a2b37b4859df2011b200af13844a SHA-1: 3762c682deae2bf8a2a2d19c62e8cbd6c87f8a7e SHA-256: c8ce26280fe7556cbe4bdcd5e4b8cc8e9780199f11333eabe29d4ae156baf58a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as a malicious Excel document with a ClamAV detection signature indicating it is a Qbot dropper. This suggests the file's primary purpose is to download and execute further stages of the Qbot malware. No specific IOCs were extracted from the provided evidence.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0