Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f93f459b34b252ff…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1b65cc92924ca6c00160bfe98d724a6d SHA-1: 2b6810ac1a0cee321ca3de61fdb4f8e757b88653 SHA-256: f93f459b34b252ff1e0275262f4b90e1fdb18ac7efce634906e9b8dcc45dbfe3
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. This type of file typically uses malicious macros or exploits within an Excel document to download and execute the Qbot malware. Further analysis would be required to confirm the exact delivery mechanism and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0