Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 b59d4b04fdfbdb4b…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: de0430db752fab4c0f6532f748a40b5a SHA-1: c3186f558d422c4ea83787f4de1415b734dc6c8d SHA-256: b59d4b04fdfbdb4ba6cbb71d11e7c5672023a13913c23c0341121f02a8f63f81
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user to open the malicious attachment, which then executes the embedded payload. No VBA or scripts were extracted, but the ClamAV signature is sufficient for attribution.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0