Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fcd2eba06ac0219a…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 415408a85ff00c6c1b11ad4d55ba2b5d SHA-1: 3b5bf31991be6419c4376650d4f7ebbfc45d0bc4 SHA-256: fcd2eba06ac0219a3f7a249b9145d9b5270c8c5b34d8b75e966fe105e14f388a
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

Static analysis identified the file as a malicious Excel document. The ClamAV heuristic specifically flags it as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating its role as a Qbot downloader. The file's purpose is to likely execute malicious code or download a secondary payload upon opening.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0