Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fade52ce65f2eabe…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 158afd4331747b23b3a47c1a159c47e8 SHA-1: c1d1bdc24e7fae2f40a0632133cfd059e3bcbe7b SHA-256: fade52ce65f2eabe3ca4ea3e78fc2fa316006861d68062b5c43fbf4c05503aed
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. As an Excel file, it likely uses macro execution or exploits to deliver the Qbot payload. The SHA256 hash is provided as a primary IOC.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0