Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d1f468565023a209…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 49e71f35633606c1579cde07bd8ff15a SHA-1: e6bac643aabfcccbc83ea1950c1af031801a841f SHA-256: d1f468565023a2092c76418c2ea1bd4a33a880612cf45c6434d34b44de59b5d8
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic explicitly identifies this file as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a Qbot dropper. The file's nature as an Excel document suggests it is delivered via a phishing attempt, likely spearphishing, to entice users into enabling macros. The primary function is to download and execute a secondary malicious payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0