Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 ead050a4ddcb81cd…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 83a2c631761882c08a3b51aab14d5155 SHA-1: f08c89da9038d2ddf8b5c604c2b816b128de44b7 SHA-256: ead050a4ddcb81cddfcbc1c6a12e28a7e46bb45f9536004fcc09cf2dba7b26e2
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No further IOCs or script content were extracted for detailed analysis.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0