Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 cab150e3b5fb2129…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 446d481723d5f82c808fca3e94cf85ee SHA-1: 77a56998350a7da3e52a9f003846494d158df73d SHA-256: cab150e3b5fb2129b9409c1b5fa0719fa1da3e1966596e5e15244349058f69ea
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot variant designed to deliver a secondary payload. The detection suggests the Excel file likely contains malicious macros or embedded objects that, when executed, facilitate the download and execution of further malware. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0