Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e97b8c0ae8c89510…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: dbb764bbcf3d2248f06f654052c25aba SHA-1: ce8499fff1f3fe006e34d32702d629d24cbf673d SHA-256: e97b8c0ae8c89510c1ca2ac41ecc20b5feae944067612a55e7d264757803efab
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop additional malware. As an Excel document, it likely employs macro execution or exploits to achieve its objective. The primary attack vector is likely spearphishing, with the document serving as the initial lure.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0