Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e68bdc0eed31579a…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 8ce6dbf43df3d835bd935ab4cf68b427 SHA-1: 14c70858f693529c7d37f6a2e5b98bf50131bc79 SHA-256: e68bdc0eed31579a206740af8365d69923e0b80a7c8cbde1623d26940b5ad50f
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were available for analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0