Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 cd48678a82991384…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 07e3277b8c544231dab03aedca2fa42e SHA-1: f09341130a62abaaa6ba71c00f684679a4a89cf2 SHA-256: cd48678a829913845adae5acc14d1418ded2d6ca69593b1963675709ba77add1
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern involves spearphishing attachments, where users are tricked into opening malicious Office documents. This file's detection signature suggests its role is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0