Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fc0a3aedfaab440f…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: bf1b9f16ee336ee893090153f285f828 SHA-1: 6f26ff62d8256d8d575355580883f7e33f9fb7ff SHA-256: fc0a3aedfaab440f6f27f37acb536835edd223e94e10eef458a9a99791821454
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial stage to download and execute further malicious payloads.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0