Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f7440d0604a672a5…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: e3dcd59209395849f48223d59f173de1 SHA-1: 7b81a55e6e4669d0bf4891b11a2f15083fe39598 SHA-256: f7440d0604a672a59019fd937584166c18a8999a1cfd73baf47b3ec0e3914c68
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it belongs to the Qbot family and functions as a dropper. The primary attack pattern involves luring a user to open a malicious Excel file, which then likely executes a payload. While no specific script content was provided, the detection name implies the execution of malicious code.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0