Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 aff47184b3d1247b…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 6f8ed8277082b11660d60fb6cb5c7551 SHA-1: 0ca7824b130345cb8ee09e75b3f44a9a010e2639 SHA-256: aff47184b3d1247b623ccbc05301a16b472d98175b050846a622785d957264a1
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The critical ClamAV heuristic identifies this XLSX file as a Qbot dropper. Qbot, also known as Qakbot or Pinkslipbot, is a banking trojan and information stealer often delivered via macro-enabled documents. This file's purpose is likely to download and execute a further stage of malware onto the victim's system.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0