Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d2c4a7fc4a63be92…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5fc70b7bf479ea7d8a7c2d8a5c672ac1 SHA-1: 478b73435cb149e72bbd4e42141ab346eab49cb6 SHA-256: d2c4a7fc4a63be923fda8210cb97f111e44a0c4df652d0fa05f3c5f77ee00e5e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1105 Ingress Tool Transfer

The file is identified by ClamAV as a Qbot dropper, indicating its purpose is to download and execute a Qbot payload. The heuristic firing directly attributes the malicious nature to this family and its dropper functionality. This suggests a spearphishing attachment attack pattern aiming to deliver the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0