Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 2ff7c7df7243604b…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 63295d9b1efbc178f26985305291979e SHA-1: d14e9ecc73b172bec984fb9be12fac2ae9cbf72d SHA-256: 2ff7c7df7243604b4cee8eed356b5078f54738ac84e86610e3729682deafa8fb
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests a malicious document designed to exploit vulnerabilities or trick users into enabling macros to download and execute the Qbot malware. Further analysis would be required to confirm the exact delivery mechanism and payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0