Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f9bd083a1dcc29a8…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3759c8592c80c0ae74104c779a1e669e SHA-1: 670a157bc9294942216b06d053c3b4f801d52231 SHA-256: f9bd083a1dcc29a88fb909d601e3cfeaf49e5ea3027083b0be9ea954254f5a83
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. The primary function of such documents is to trick users into enabling macros, which then download and execute the Qbot malware. Further analysis would be required to confirm the exact delivery mechanism and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0