Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 bdf6d1d2aed2b414…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 6336461bf4dd208f6163cf0a19336f76 SHA-1: 3bc28dad3ebfb415e4b15c4ecbcaca9ae30c86d8 SHA-256: bdf6d1d2aed2b4146d4152ce6a9ac3d2ba5808c19c777e93d1ad99d71249e332
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: Malicious File

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user to open the malicious attachment and likely execute embedded macros, which would then download and run the secondary Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0