Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fe269430ebbed61b…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: e643ec05b62d81679962325d26ee3c6e SHA-1: ded41256635afa750ffdf9805e896a41159d7a3f SHA-256: fe269430ebbed61b3f03be136a6097e0bd1eab17927265e16cdc881b5264d2fa
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it is a Qbot variant designed to drop and execute a malicious payload. The file's nature as an Excel document points towards a phishing or social engineering attack vector, likely using macros to initiate the infection chain. Further analysis of the dropped payload would be required to detail its specific actions.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0