Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 96bfce5b0284d853…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 19d3cfefcbb5f7c5783c0fefa058fa6f SHA-1: b88f23721fb6004b11116c818f9bd59f39aed4c1 SHA-256: 96bfce5b0284d8537400bc24ad4b23e9027652e69847c3c7644f45a5c2853014
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it leverages malicious macros or embedded content within the Excel file to initiate the infection chain. This aligns with common Qbot distribution methods.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0