Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 aed269302d062797…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 2dd4f09b7c1baec29b6c41c82724866b SHA-1: 0e770340cedd2845baddd3e5cfbc097f5b1c2043 SHA-256: aed269302d062797bf13d100d00fb627f7b76a11373dc35829ead5dcc528e4dc
60 Risk Score

Malware Insights

Qbot · confidence 85%

MITRE ATT&CK
T1204 Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it functions as a dropper for the Qbot banking trojan. While no specific scripts or document body content were provided for analysis, the heuristic detection indicates a malicious intent to deliver and execute further malware. The file's metadata shows it was authored by Microsoft Excel 14.0300.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0