Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fc152dd25189ab65…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 371badef02dccf03937c3ad8860bf95e SHA-1: df51ae760ecec320a39faf5ee64f3a7a0acdb77d SHA-256: fc152dd25189ab652e9004d7f637fdd83eaffc8693184d4e01e295bce255df85
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as an Excel document with a critical ClamAV detection signature indicating it is a Qbot dropper. The presence of this signature strongly suggests the file's purpose is to download and execute the Qbot malware. No document body or scripts were extracted, but the ClamAV detection is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0