Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e07d859bef4f7721…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: cf7491bd2bce677a73f9955b013a748b SHA-1: 582e564267081da5a8544f534e129f55eb8fed97 SHA-256: e07d859bef4f77217ed284b68fee332eff1519ad0a5da138b8d3ae7cc95a63cb
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to act as a dropper. The primary function is to deliver and execute a malicious payload, likely through the exploitation of macro execution within the Excel document.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0