Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 bba6d3e57066e5f8…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 23c6a2f76e6c6e8bd13c7ffae6349453 SHA-1: cbd51e16b15651828de6dcf3fc0bf0311c5294c5 SHA-256: bba6d3e57066e5f81b3403a78755f5f7c8230bb9ffcd292138a2987ab2fd047c
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File: Malicious File

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack vector is likely spearphishing, leveraging the malicious Excel document to initiate the infection chain. The document's purpose is to download and execute a secondary payload, consistent with Qbot's typical behavior.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0