Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f7c1624edfc57c28…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: a95947c271feb04af40e1024367b4da1 SHA-1: 9ee494207dafeae9f99c485b6cec5e4a93b7f0f8 SHA-256: f7c1624edfc57c28f25ea7472e8a6222093e718b138f1ec7fc81c87f6074ac2c
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The detection name suggests it exploits vulnerabilities within Excel documents to deliver its malicious payload. The primary attack vector is likely spearphishing, leveraging the document's macro capabilities to initiate the infection chain.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0