Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 7091c472d3bcdb33…

MALICIOUS

Office (OOXML) / .XLSX

65.7 KB Created: 2022-04-29 12:58:15 UTC Authoring application: Microsoft Excel 16.0300 First seen: 2022-05-06
MD5: fffc0f12fe53dff3e391c243d72c1aec SHA-1: f819f6d32fd9cf836fec1ab30d36f4f21317bef6 SHA-256: 7091c472d3bcdb33a164302c5e8adb500e7af224ed2c08e07fdcef664b92a948
120 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1059.005 Visual Basic T1204.002 Malicious File

The file is an Excel spreadsheet containing Excel 4.0 macros, as indicated by the OOXML_XLM_MACROSHEET heuristic. The ClamAV detection explicitly identifies it as Xls.Downloader.Qbot. The extracted macro content shows attempts to construct file paths and execute them, suggesting it functions as a downloader for a secondary payload. The specific file paths and .dat filenames are indicative of Qbot's typical behavior.

Heuristics 2

  • Excel 4.0 macro sheet (1 sheet(s)) critical OOXML_XLM_MACROSHEET
    Spreadsheet contains an Excel 4.0 (XLM) macro sheet — XLM was a major Office malware vector during 2020-2022 and evaded many VBA-focused controls before Microsoft tightened XLM defaults. Even legitimate XLM use is rare in modern workbooks. The macro sheet is stored as XLSB/BIFF12 binary content, which many XML-only OOXML scanners miss.
  • ClamAV: Xls.Downloader.Qbot-aa2a2a3fd5f4342a-9950245-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Downloader.Qbot-aa2a2a3fd5f4342a-9950245-0

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
xlm_sheet_00.bin
d1b14276d961e4e701175caef6c3d02502ff9637644d54439d640cecc6840ff0
xlm-macrosheet OOXML XLM macro sheet: xl/macrosheets/sheet1.bin 2501 bytes