Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 c9e9a7eaf885f39b…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d5d36891fd64fba19fc0f8e0cf0f368c SHA-1: 9d7050d3405ad93b0f5f4ee8678f40c1e68e7d70 SHA-256: c9e9a7eaf885f39b5b189fc30ee39e6e1b71be96fb29689d2bb158c3d823dd53
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating a Qbot family infection. As an Excel document, it likely employs social engineering to trick the user into enabling macros, which then execute the malicious payload. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0