Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 561253edda427a35…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 7620932073c792efd86dad106533a888 SHA-1: 7d014df7cac473d273aab3a04c3c688f7f34882d SHA-256: 561253edda427a350c5eb75fd7c8b7d57bff12a0f1718994e8f314eeac6e5645
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it exploits vulnerabilities within Excel documents to deliver its payload. The primary attack vector is likely spearphishing, leveraging the malicious Excel file as an attachment.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0