Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 cab2269c94b8af09…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: fbf36652a6df6a247ead242ee0397c9a SHA-1: c775b3eaa19a8e866ed7ff4fc914e014b05b85e1 SHA-256: cab2269c94b8af09eb73adb1c696a0703c181cbdc98bbe5cf10afbbd108338b3
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1204 Malicious File Execution

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop and execute further malware. The primary function appears to be acting as a downloader for a malicious payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0