Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d1ccce9cbc35f08a…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b93cbd2155a79f7f51bfec73b7844a13 SHA-1: 1815b7fe7754ef6fcbf44ea5b47e6639e74fda8e SHA-256: d1ccce9cbc35f08ac1f5d256404a94e72f8424a8e0ee89f584ec8bda79d6afaf
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves delivering this malicious Excel file as an attachment, likely via spearphishing, to trick users into opening it and enabling macros.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0