Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 20220a7511627477…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: dd1b2daa465fedf4597e79f19c1da993 SHA-1: 076f85cd84c0cf44e454ad5012eb9f0fa8294fa3 SHA-256: 20220a75116274771edcb6bceec9e9b9f9fe90b19927e20ae39231e6047abb13
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user to open the malicious attachment, which then executes the embedded payload. No document body or scripts were extracted, but the ClamAV signature is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0