🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05289fdf2a8453e355040550b55a85aaff066dfd3e4fe9ff8558c54e6a12071f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 5


Intelligence 5 IOCs YARA 4 File information Comments

SHA256 hash: 05289fdf2a8453e355040550b55a85aaff066dfd3e4fe9ff8558c54e6a12071f
SHA3-384 hash: 6d1ec135c493eaf10a2c50c81193e32426a3f47ba467c3dde85ac4f3b863f00637a24c92e9bfc49c12e4dca1001947c7
SHA1 hash: 67bf413767431f35373b70d50809c7b7f15626fc
MD5 hash: 5748e5ce146f5356ca0fd973d4ceb57c
humanhash: kitten-shade-autumn-early
File name:details_9626.iso
Download: download sample
Signature Quakbot
File size:229'376 bytes
First seen:2022-10-19 06:25:41 UTC
Last seen:Never
File type: iso
MIME type:application/x-iso9660-image
ssdeep 3072:12IsZGaSWyGN4+79gLciVy/uxHGNi/+Qv2VlRgg6NHe0Gb:12IUVyuN9W1xHG0/are9e00
TLSH T14824AEA435907178D5AB0136D42F3346E2729A5E685F8158B00DDCD83FACE57CA23EAB
TrID 99.6% (.NULL) null bytes (2048000/1)
0.2% (.ATN) Photoshop Action (5007/6/1)
0.0% (.BIN/MACBIN) MacBinary 1 (1033/5)
0.0% (.ABR) Adobe PhotoShop Brush (1002/3)
0.0% (.SMT) Memo File Apollo Database Engine (88/84)
Reporter cocaman
Tags:IcedID iso Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
202
Origin country :
n/a
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:sold.cmd
File size:377 bytes
SHA256 hash: ecd3014dc55f0f77c1f9c98522749c3633e2c0d6302725e0334ae8eb0ea1cc3c
MD5 hash: a9d13e6527c49efcc49b4ff8d0303e0d
MIME type:text/x-msdos-batch
Signature Quakbot
File name:perfected.png
File size:31'058 bytes
SHA256 hash: 2960138c9f6c9720a210213eeb3670006abe932523c475644a0cfdea0249c1de
MD5 hash: e13055fce60647dd11ee29898680b047
MIME type:image/png
Signature Quakbot
File name:amidst.des
File size:130'048 bytes
SHA256 hash: 261faead66b2fd629dd68a95e5185dc23f9619806b357cdb9482d1dad3780c9f
MD5 hash: 2f751738132081821c6c3f9a7af5c762
MIME type:application/x-dosexec
Signature IcedID
File name:facts.lnk
File size:1'839 bytes
SHA256 hash: 4cb696f6a50cb2b73bf9a4d68f41a44d3c2486cd3fae518179aaaf69f5746ed9
MD5 hash: 28c829d86eeebda80fbb7a80919ee805
MIME type:application/octet-stream
Signature Quakbot
Vendor Threat Intelligence
Threat name:
Win32.Trojan.IcedID
Status:
Malicious
First seen:
2022-10-19 07:17:14 UTC
File Type:
Binary (Archive)
Extracted files:
5
AV detection:
6 of 42 (14.29%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:icedid campaign:2959887884 banker loader trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Loads dropped DLL
Executes dropped EXE
IcedID, BokBot
Malware Config
C2 Extraction:
salimjizita.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:iso_lnk
Author:tdawg
Rule name:Qakbot_IsoCampaign
Author:Malhuters
Description:Qakbot New Campaign ISO
Rule name:SUSP_EXE_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contains an Exe file. Does not need to be malicious
Reference:Internal Research
Rule name:SUSP_VBS_in_ISO
Author:SECUINFRA Falcon Team
Description:Detects ISO files that contain VBS functions
Reference:Internal Research

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments