Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f788c8b0bfe8c3f4…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b7d9f9b7063a0979d969abbbf0682347 SHA-1: 27d37ee32cab3cf2a4e2fa9d5b9e32d28cf849c6 SHA-256: f788c8b0bfe8c3f43c13ab0a8621dbb7b675fba43335df9f5cdd786510694c1e
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests the primary function is to download and execute a malicious payload, likely leveraging macro execution within the Excel file.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0