Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 ab764f4b1f26b222…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: c85fafdb22e435a2d0f579489a5cc03c SHA-1: 0d27151b77f83fcf7ce62b290d075ed0f993b92e SHA-256: ab764f4b1f26b22295b642b0378cc736533f1044f863307bc788d6bfb9e1cb80
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as a Qbot dropper. Qbot, also known as Qakbot or Pinkslipbot, is a banking trojan primarily distributed via phishing emails with malicious attachments. This detection strongly indicates the file's purpose is to download and execute the Qbot malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0