Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 e5ceb8b12923da50…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 708c7da2c92c336d5b7a57121009132b SHA-1: 93adb7648c6b9ff0bdf738bd37020ec748213043 SHA-256: e5ceb8b12923da5000f5b0c15c57d5b38d38462d27253c28fc335cd2270a5f96
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user into opening the malicious spreadsheet, which then executes the embedded payload. No further IOCs were extracted from the provided evidence.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0