Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 a907851f1d13a520…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0e5596cf1eb0a7142d5c8f604a92650e SHA-1: b10da5ed4eb105b23b8c43fdf04850e4544b8dfb SHA-256: a907851f1d13a520652b4b42857ddf87cad80b98d009adf3161517dd3637b4e6
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The critical ClamAV heuristic identifies this XLSX file as a Qbot dropper, a known banking trojan. This suggests the file's primary purpose is to initiate a download chain for further malicious activity, characteristic of Qbot's typical infection vectors.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0