Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c8d8cf6fab7f7850…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d2bc926b3825f4285e75446de3747214 SHA-1: aaaa96722c646206d9c513f8922a97c45fe36fcb SHA-256: c8d8cf6fab7f785014ba98f060b5f0518a482d5f30730188e4661674699be01a
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The document's metadata shows it was created in 2006, which is unusually old for modern Qbot variants but does not preclude its use as a dropper. No further IOCs or scripts were extracted for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0