Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d770d19412a20c82…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7f2bb1e6137f54a86f65f17234595188 SHA-1: 2c950f8f293ddd34c299f811c7f00ae6091519a3 SHA-256: d770d19412a20c82f80504b7b0ee266254b9f0efc876f6d897f4625f5db21ea0
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', a known Qbot variant. This indicates the Excel document likely contains malicious macros or embedded objects intended to download and execute the Qbot malware. The primary attack pattern involves luring the user into opening the malicious attachment and enabling macros, leading to the execution of the secondary payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0