Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d2b40f85beeec9fc…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: afd3fb0ce9c64bf569d51234fffb061a SHA-1: 7454584ba299cfe8bf268986da7af3cdc81b94b8 SHA-256: d2b40f85beeec9fc8439c4a593bda1c6c923dce7e04a57db04595a40a82d1785
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The critical ClamAV heuristic firing, 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggests this Excel file is a dropper for the Qbot malware family. Dropper documents are typically used to lure users into opening them and then execute a secondary malicious payload, often through macro execution or exploiting vulnerabilities.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0