Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 29a93b90f091257b…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 25080b192e64694e25ed2992f7d7e66f SHA-1: be5e37f7e67ec80ba26b10aee14fdaa59127f21f SHA-256: 29a93b90f091257b37595a082a8b72e9369814df123508cd7781b4aa1525f919
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1105 Ingress Tool Transfer

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it exploits vulnerabilities within Excel documents to deliver its malicious payload. This pattern is consistent with Qbot's typical distribution methods.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0