Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e73c6abb83391a74…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 024d4347c203f2f952c72192a8db0eb1 SHA-1: 5fd5b32da6303de44049f29a02f2a0a1efacf19b SHA-256: e73c6abb83391a7430c827a635022199897d523cd825ea54f515620406318823
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1204 Malicious File T1204.002 Malicious File: User Execution

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop and execute additional malware. The primary function appears to be the initial infection vector, relying on user interaction to trigger the malicious payload. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0