Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 de242fac5f5c2d20…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: aa5fa410e2012163e6ff766e4c205f2b SHA-1: 3db21a5f3a4fccae8a2eed1b162b3aba4db5a904 SHA-256: de242fac5f5c2d200191822e24c67e3a72f493f0cb2d35e3d423407988599d75
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified as a malicious Excel document by ClamAV, specifically flagged as 'Xls.Dropper.QbotDocu12020-9818439-0'. This strongly suggests it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves spearphishing attachments to deliver the initial malicious payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0