Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e29012a7bb41b4d1…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 5690386b35ec6433bbf718d51c4bc0df SHA-1: cb03de9700eb1b095d996c30ca6bed375f6ee67d SHA-256: e29012a7bb41b4d1f6dd11b75c3741f00a5e6b6eb64bb006d4bed6018393cd1e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment T1204.002 Malicious File

The file is identified as a malicious Excel document by ClamAV, specifically flagged as a Qbot dropper. This indicates the document's primary purpose is to download and execute a secondary malicious payload, likely Qbot malware. The SHA256 hash is included as a primary indicator of compromise.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0