Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 7d2d3f8a0f014542…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 70815612bd8f15d000fc7b9407afd4d5 SHA-1: c00024d09c33b7b9fb3e510de9edc5248e3682de SHA-256: 7d2d3f8a0f014542e9eeffecb09b1fd89b81528be85ca9d115ed14be3eca3335
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: User Execution: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. As an Excel file, it likely relies on social engineering to trick the user into enabling macros, which would then execute the malicious payload. The SHA256 hash is included as a primary indicator.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0