Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 ed1b60e08a05081a…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 565df90d2c2b9a20a62f368d0e286e63 SHA-1: 55bc959ab5553957f2cef36592158c415bb51096 SHA-256: ed1b60e08a05081ad6adb47d55c1b7dba46e14d1b15f4cf5320dd2188e23979e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant. The nature of dropper documents is to facilitate the download and execution of further malicious stages, typically initiated by user interaction such as enabling macros. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0