Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 9d180f36a634e12c…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: a9ee84da8f0d712142ecde8f804743d3 SHA-1: 715fa600088fbd0a6fe83a5883a4c65aaf207c22 SHA-256: 9d180f36a634e12c93ef377b5e07d96ba70eec9439a819b5ea9ac67b21f664e3
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it is a Qbot dropper. Qbot is known to be distributed via malicious Office documents, often using social engineering to trick users into enabling macros. This file likely serves as an initial infection vector for the Qbot banking trojan.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0