Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 277910ab1c489e3e…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 458efc59bc8c9c4d3c620e8f67ee3f1a SHA-1: de8d1818a31b7569e489b664f7f9a44f3b7db685 SHA-256: 277910ab1c489e3e290e6faebd48750ebf947655a9e95793ebbf2374b52f5f1e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it exploits user interaction with the Excel document to initiate the malware download and execution process. This aligns with common Qbot distribution tactics.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0