Qbot — Office (OOXML) / .XLSX malware analysis

Static analysis result for SHA-256 fcc29d8ed575feb3…

MALICIOUS

Office (OOXML) / .XLSX

23.6 KB Created: 2006-09-16 00:00:00 UTC Authoring application: Microsoft Excel 14.0300
MD5: b80c93700a168fbded8a61a7987e157f SHA-1: 6e93683b762ff4348bafb59d283438e606d05e9b SHA-256: fcc29d8ed575feb39ff62f159706c489cb6c3875b1114bee1490f4d02a60fc57
60 Risk Score

Malware Insights

Qbot · confidence 95%

MITRE ATT&CK
T1566.002 Phishing: Spearphishing Attachment T1105 Ingress Tool Transfer

The file is identified by ClamAV as 'Xls.Dropper.QbotDocu12020-9818439-0', strongly indicating it functions as a dropper for the Qbot banking trojan. While no specific VBA or script content was extracted, the heuristic firing suggests the Excel file contains malicious macros or embedded objects intended to download and execute a secondary payload, a common Qbot delivery method.

Heuristics 1

  • ClamAV: Xls.Dropper.QbotDocu12020-9818439-0 critical CLAMAV_DETECTION
    ClamAV detected this file as malware: Xls.Dropper.QbotDocu12020-9818439-0