Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f373ba04b35823a8…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: c9983452e5872f67f65480a714316218 SHA-1: b2e0fe70609cf78b2aa1f7cbe3d0cc30caee4ebb SHA-256: f373ba04b35823a87efbb70383dfc9688e837934035c8bfd0ca343d6ca18dcc7
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1204 Malicious File Execution T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of document typically relies on social engineering to trick the user into enabling macros, which then execute the malicious payload. The primary attack pattern involves delivering the Qbot malware through a malicious Excel file.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0