Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f5893329d21f8176…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: c1cba569e3c22c9b2f51a5c8af8541a2 SHA-1: d14fed89a61d82fb18cf23ef89e33c33a42166e9 SHA-256: f5893329d21f8176dcf125b94f52ca3333f30ed568e5f01ea0c1511728c6e8cd
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it exploits vulnerabilities within Microsoft Excel to deliver its malicious payload. The primary attack vector is likely spearphishing, with the Excel file acting as the initial attachment.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0