Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fb5f7ce8a75773da…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 1cd1c6a7c3f32af919f249227f50482a SHA-1: 91e3bbecb15726934e4fd036785a4d45734ddc13 SHA-256: fb5f7ce8a75773dad98768a1707909d224a5ea0c6b4d7b40a275f6f9d4dbefb1
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic 'Xls.Dropper.QbotDocu12020-9818439-0' strongly indicates this Excel file is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial access vector for Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0