Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e50e422fb0f8db52…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b9ec6fb91e0350b07c0d7fb4706aa46e SHA-1: e56ab103a410728e402189452c0b8518c6f5720e SHA-256: e50e422fb0f8db52b7c621a03fd2b47368d2e11b3e6b3d9d7c946f76c711229d
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1204 Malicious File T1059 Command and Scripting Interpreter

The file was detected by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', indicating it functions as a dropper for the Qbot malware family. The detection name suggests it is designed to download and execute a secondary payload, likely leveraging macro execution within the Excel document.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0