Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 d515a5e03b0f3574…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 38fc9ee7f22a8088db417f3cf5341f59 SHA-1: f2666f2b64d990d8a80849955b2f7503c8684bcc SHA-256: d515a5e03b0f35746d58f254db00b2202458fff83a8c360fed1d93dff3200ef6
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The document's structure and metadata do not provide further details on the specific delivery or execution mechanism, but the detection name itself is sufficient evidence of its malicious intent.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0