Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 f9d2519f45c4468c…

MALICIOUS

Office (OOXML) / .XLSX

21.4 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: 0e4be41b66ed1d42ae9ab9ee455e7ac6 SHA-1: 72b0a2c3320a1ed72d805ce7832629cf0ec90c23 SHA-256: f9d2519f45c4468c0445232d1fa9a77fc9272805577de715aa6c19143c1b445f
60 Risk Score

Malware Insights

Qbot · confidence 90%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment

The file is an Excel spreadsheet identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. The primary attack pattern involves luring the user to open the malicious attachment, which then executes the embedded payload. No specific scripts or document body content were provided for further analysis of the execution chain.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0