Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d002bab79e1e3ecd…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 176b3fcf8d8b96c01d8ff96b4160bb2d SHA-1: d32ea2c9d67af039a607de62574621bb501ed493 SHA-256: d002bab79e1e3ecd8960de3695cebe355501279536837e825dfa808119fcf7b2
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1204 Malicious File Execution

Static analysis identified the file as a malicious Excel document. The ClamAV heuristic specifically flags it as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly suggesting it functions as a dropper for the Qbot banking trojan. The document's primary purpose is likely to trick the user into enabling macros, which would then download and execute the next stage of the malware.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0