Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 dd1d62cbc341d06a…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 44106e46ef07184de9ecb575de06d776 SHA-1: c9ac95ba6152b0de410f579b0d7379382ac03954 SHA-256: dd1d62cbc341d06abf7d7d301d2968742423effeceb2a9185b4b23305f572499
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. Further analysis of the document body and scripts was not available.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0