Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d5db18fe611200da…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 42646bbb3501e8e3ef5a8870b3a250a5 SHA-1: 4053d0dac8431b4f2d62cba742d4f2ab7c6f5816 SHA-256: d5db18fe611200dadb22c94fde12a49f9d513ad1aa7f82e7d629273d780628d7
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its use as a Qbot downloader. The metadata shows it was authored by Microsoft Excel, a common vector for macro-enabled malicious documents. The primary function appears to be the delivery of a Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0