Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f8aa990f6ae954bf…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 85194b380113b797de460f9dc8ea636f SHA-1: 217a6d87ec12fcca017016cd8d3dad6f0418d6fb SHA-256: f8aa990f6ae954bfd59a310b7fcd944527db54da396813d536155dd11ff2da34
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary attack pattern is likely spearphishing attachment, where the user is tricked into opening the malicious Excel file. The file's purpose is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0