Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f31a8e7fd587f287…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2151ac41db8a05df63e82cf45d2ac84b SHA-1: 8dc7a7bc984e3898cbdfefbdf5a6993b0d867597 SHA-256: f31a8e7fd587f287edc83b5a322adae3cc6501292f158fc0d0965f3ca663791a
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it functions as a dropper for the Qbot malware family. As an Excel document, it likely relies on social engineering or user interaction to execute its payload, aligning with spearphishing attachment tactics. The primary IOC is the file's SHA256 hash.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0