Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 55bf98efbb3fdf9b…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: dac848131c77aad49b25d4fca24f177a SHA-1: d0be618c009d6ff7862cdef8782d2b2ee21dee35 SHA-256: 55bf98efbb3fdf9bd04bd5b03dcf97519cc40fb381eab254d9c3ae921a35615b
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial infection vector for the Qbot banking trojan.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0