Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 1dfde681b7190e64…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: fc45d96009a28df38f5024fb9e8d1228 SHA-1: 6f15f305772a9f76a077aa4c4f4c638c90b36212 SHA-256: 1dfde681b7190e641bc7f9e1e7a74b7c427814144fd076d50971aa02a8b98bf4
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The ClamAV heuristic 'Xls.Dropper.QbotDocu12020-9818439-0' strongly suggests this Excel file is a dropper for the Qbot banking trojan. Such droppers typically rely on social engineering to trick users into enabling macros, which then download and execute the main payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0