Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e4b4a642049f5163…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 688491c3c47388ef19ebde624f91e539 SHA-1: f7d10da31866764da069b8b7da0df8ccd6bdd4ea SHA-256: e4b4a642049f5163062d15ab9478493a78ec5cc96e975e279a316e0b2dcd30aa
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating a Qbot variant. As an Excel document, it likely employs social engineering to trick the user into enabling macros, which would then execute the Qbot payload. The SHA256 hash is included as a primary indicator of compromise.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0