🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689
SHA3-384 hash: ff5c329bd335651e39d9c5c3f6d5b5a7bd122ad8d883b380efda33ef33bff477182412f4e133e11b015806412f1fd772
SHA1 hash: c7a18b534aada84a7f26adebd0e5363fd7b0d3ca
MD5 hash: a2c1f27adb35d8a67248ff2e2b636fd2
humanhash: venus-white-venus-quiet
File name:0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689
Download: download sample
Signature Quakbot
File size:497'664 bytes
First seen:2022-03-03 14:50:03 UTC
Last seen:2022-03-03 16:49:20 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 0383b6e78c7f005efbff386cee23786c (6 x Quakbot)
ssdeep 12288:vnKiMBsfsXtxbohL+/JkjFbK5BFHGiIDwqJ6dYiH:vA6fevoVaJmFbeBF5IDt6dY6
Threatray 137 similar samples on MalwareBazaar
TLSH T1A0B4BFB875146CE1E6BF163BC995ADE803762632DE87D8CE506477C709733A1FE1280A
Reporter malwarelabnet
Tags:dll obama163 Qakbot Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
172
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Searching for the window
Threat name:
Win32.Backdoor.Quakbot
Status:
Malicious
First seen:
2022-03-03 14:51:10 UTC
File Type:
PE (Dll)
AV detection:
20 of 42 (47.62%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:obama163 campaign:1646294115 banker stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Qakbot/Qbot
Malware Config
C2 Extraction:
144.86.64.220:443
124.41.193.166:443
180.183.100.147:2222
175.145.235.37:443
117.248.109.38:21
5.95.58.211:2087
197.164.171.102:995
176.57.126.138:443
197.2.10.67:443
32.221.231.1:443
78.100.194.138:6883
89.211.185.240:2222
190.189.33.6:32101
193.253.44.249:2222
76.70.9.169:2222
67.209.195.198:443
39.52.43.1:995
75.67.194.204:443
80.11.74.81:2222
64.231.210.71:2222
93.48.80.198:995
217.128.122.65:2222
41.43.13.54:995
180.233.150.134:995
38.70.253.226:2222
120.150.218.241:995
196.203.37.215:80
89.101.97.139:443
92.99.229.158:2222
91.177.173.10:995
103.230.180.119:443
182.191.92.203:995
80.14.188.219:2222
111.125.245.118:995
206.217.0.154:995
197.167.46.225:993
63.153.150.20:443
96.21.251.127:2222
2.50.41.69:61200
74.15.2.252:2222
5.32.41.46:443
76.25.142.196:443
141.237.140.181:995
114.79.148.170:443
209.210.95.228:32100
81.213.206.182:443
139.228.65.100:2222
70.46.220.114:443
190.73.3.148:2222
103.87.95.131:2222
183.82.103.213:443
92.177.45.46:2078
89.249.215.26:61202
197.167.46.225:995
41.84.232.135:995
39.49.3.69:995
144.202.2.175:443
75.99.168.194:443
172.114.160.81:995
47.180.172.159:50010
140.82.49.12:443
121.74.187.191:995
176.67.56.94:443
66.230.104.103:443
118.189.242.45:2083
119.158.98.225:995
136.143.11.232:443
47.180.172.159:443
102.65.38.67:443
105.184.116.32:995
58.105.167.35:50000
24.178.196.158:2222
208.107.221.224:443
76.69.155.202:2222
176.88.238.122:995
41.228.22.180:443
188.50.5.129:995
76.169.147.192:32103
173.174.216.62:443
47.23.89.60:993
75.99.168.194:61201
197.89.17.163:443
2.50.27.78:443
118.161.12.23:995
70.57.207.83:443
128.106.123.103:443
172.114.160.81:443
86.98.156.238:993
31.215.70.101:443
86.98.11.110:443
210.246.4.69:995
120.61.2.163:443
144.202.2.175:995
89.137.52.44:443
39.44.58.183:995
118.161.12.23:443
102.140.70.201:443
103.139.242.30:990
173.21.10.71:2222
185.249.85.209:443
71.74.12.34:443
189.253.111.123:995
173.170.224.168:995
220.129.52.36:443
67.165.206.193:993
47.156.131.10:443
47.156.191.217:443
201.170.176.129:443
86.198.170.170:2222
73.151.236.31:443
201.103.17.10:443
70.51.153.159:2222
72.12.115.90:22
191.99.191.28:443
63.143.92.99:995
98.17.34.83:995
100.1.108.246:443
108.4.67.252:443
24.55.67.176:443
105.225.173.49:995
72.27.20.126:443
161.142.53.161:443
78.96.235.245:443
208.101.87.135:443
95.245.155.237:443
45.46.53.140:2222
94.59.139.37:2222
109.12.111.14:443
78.17.143.201:443
82.152.39.39:443
86.195.158.178:2222
69.14.172.24:443
68.204.7.158:443
41.230.62.211:993
186.69.101.54:443
2.50.37.117:443
41.84.225.153:443
86.98.149.243:995
190.206.211.182:443
81.229.130.188:443
5.88.12.21:443
83.110.218.94:32101
39.52.200.124:995
105.156.232.83:443
80.123.141.226:443
186.64.67.40:443
103.139.242.30:993
176.110.96.225:443
202.56.44.112:993
Unpacked files
SH256 hash:
0838cd11d6f504203ea98f78cac8f066eb2096a2af16d27fb9903484e7e6a689
MD5 hash:
a2c1f27adb35d8a67248ff2e2b636fd2
SHA1 hash:
c7a18b534aada84a7f26adebd0e5363fd7b0d3ca
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments