Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d4cf1ccdef3bb9ae…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0e9a9576400b466aa875222c2582c613 SHA-1: 74ac2a2c5631b332a60b4ad506487f729c2f76e2 SHA-256: d4cf1ccdef3bb9ae44eb3593b9ba17f33963adc89399d6b712861ebc5519b267
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves spearphishing attachments, leveraging the malicious nature of the Excel file to initiate the infection chain. Further analysis would be required to identify specific dropped payloads or C2 infrastructure.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0