Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d7ebe75be1226281…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: e5e9a9eb524f5921ec80f5685a525f6c SHA-1: 21917ff89710bfede0890d51f29d9e38364babc2 SHA-256: d7ebe75be122628109b89a276d84f292dcc2cb762308d26d19f47c6ff77a83ec
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is part of a Qbot distribution chain. Qbot is known to be delivered via macro-enabled documents, which this file likely is, serving as a dropper for the main payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0