MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0758b43a955dc7f5f529c71d6100de1e0d91ffc50979bf9cda950e4d2fe6545a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara 1 Comments

SHA256 hash: 0758b43a955dc7f5f529c71d6100de1e0d91ffc50979bf9cda950e4d2fe6545a
SHA1 hash: 7740392d23f140a65fb36d137c473006cc053447
MD5 hash: 64e7d928c497f9a33a3e999b5d933a12
File name:SecuriteInfo.com.Trojan.Inject3.40354.3196.21002
Download: download sample
Signature Quakbot
File size:762'368 bytes
First seen:2020-05-22 10:51:45 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash f775e5f2c7122a9f4550feacec30f2d0
ssdeep 12288:HgU3965wVaFgq6LuM+0D2PNEt2vxNIGeOerLIX:7kFgdnUVEdkerLI
TLSH 3BF47A0BEA3F47A7DCC68A31CDBDB53A411A5CBBD23693067100FE9E9AF225115D62C1
Reporter @SecuriteInfoCom
Tags:Quakbot

Intelligence


Mail intelligence No data
# of uploads 1
# of downloads 32
Origin country US US
ClamAV SecuriteInfo.com.Trojan.Inject3.40354.3196.21002.UNOFFICIAL
VirusTotal:Virustotal results 44.44%

Yara Signatures


Rule name:win_qakbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments