Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f0888cca38d7a3d1…

MALICIOUS

Office (OOXML) / .XLSX

29.5 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 6c6d8f54d89fe115408ed7705d8a8dae SHA-1: 16b8428c9813d4560c9afe77baeae06a504465f2 SHA-256: f0888cca38d7a3d144fbd8ca039abd502f751fea6e1a10a8350f1b8eb48c1661
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel document identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves delivering this malicious document via spearphishing to entice users into opening it and potentially enabling macros, which would then execute the Qbot payload.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0