Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d323a7dc6816166f…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 25f01710f144db7aefeaa27a430b3f88 SHA-1: 982e5557a6a084d3587c645f2c040a626deb2711 SHA-256: d323a7dc6816166fc62b99ca3416d6c7147372bc99ecd78ba41395300e86bfb1
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The file's metadata shows it was authored by Microsoft Excel 14.0300, and the creation date is from 2006. No document body, scripts, or URLs were extracted for further analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0