Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fdae7216369004da…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 701787d95eb2f70483c04f2fa727f462 SHA-1: 2564d770380ae71577479b4bb1a0d76a647cabec SHA-256: fdae7216369004da6c865b9b6b40124bdfe6aa8860b3081a83f0c4f46104565c
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic identifies this file as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting a Qbot family dropper. The file is an Excel spreadsheet, likely delivered as a spearphishing attachment, intended to execute a malicious payload. The SHA256 hash is included as a primary IOC.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0