Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a6e69ba2861a02f4…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 535e969d366c2f2563953fe43d038f19 SHA-1: 2b71e0f53f9c44a2bcc6f579ffa02298c8456c56 SHA-256: a6e69ba2861a02f403519f9b4f68b43636f1ea7da74b3c6f9100191772fc2893
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0'. This heuristic strongly suggests the document is a dropper for the Qbot banking trojan. Qbot is typically delivered via malicious Office documents, often using social engineering to trick users into enabling macros.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0