Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fbd49926dbaed0f4…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: d4cc76638cf11c4f9cdd6a080f1e6f75 SHA-1: ae8724d8a7680adc7f33382a467e33e1c5fd7c52 SHA-256: fbd49926dbaed0f4e732cf423ccbc2fe5342527ae6ba61354653ff767d06648e
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its role as a dropper for Qbot malware. The detection suggests the Excel file is designed to execute malicious code, likely through macros, to download and install further stages of the Qbot infection chain.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0