Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 cce5eda432721e01…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 3082f446832b54b180bfca94a0fe0cc8 SHA-1: 397008fe7c5ddd99e40984e9b6776e75f9a560d4 SHA-256: cce5eda432721e01b5ef069ec102d6c865ee683c07131a188af9c8c2041b07f1
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1204.002 Malicious File Execution: User Execution

The file is identified by ClamAV as Xls.Dropper.QbotDocu12020-9818439-0, indicating it functions as a dropper for the Qbot banking trojan. As an Excel document, it likely relies on social engineering to trick the user into enabling macros, which would then execute the malicious payload. The primary function is to download and execute a secondary-stage malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0