Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f7b42c0d8dcd85a2…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: ce7ddbe22596d77723466bce6ff53624 SHA-1: da673be11fdad909fb36e279dfea3746561d57d8 SHA-256: f7b42c0d8dcd85a291a6f3f7f9aea14105a158676b80fb4ef051060d3181244a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a Qbot dropper. This type of document typically uses malicious macros to download and execute the main Qbot payload. The presence of this specific ClamAV signature is sufficient evidence for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0