Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f284da036590b58a…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 91cec7b123de843c4906c7639a42e57a SHA-1: 90fd7461fba0d2cb28a0ee658dda4c1a26a02de3 SHA-256: f284da036590b58a05f5ee7fe9fa32bb8bfed4eed621e13378a0345a8defb39b
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic 'Xls.Dropper.QbotDocu12020-9818439-0' strongly indicates this XLSX file is a Qbot dropper. Qbot is known for its capabilities as a downloader and its use in various phishing campaigns. The file's purpose is to deliver a secondary stage payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0