MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0ba184cdfa520fd888599a9c62cf5e7e0a5e0a74d3cd3c7067579a8b0d93acf1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 0ba184cdfa520fd888599a9c62cf5e7e0a5e0a74d3cd3c7067579a8b0d93acf1
SHA3-384 hash: e55372db7f5bb6c90cdb198048d872526ad87081b8b8cc45e749cb132eb3f49782f703022b376e4c6dd405e536d2cffe
SHA1 hash: c842866c9d150e8ec9e85c27c45c1dfee3e8577d
MD5 hash: 03efc266b1d7f6081c752d152267e862
humanhash: nineteen-harry-leopard-twelve
File name:SK.js
Download: download sample
Signature Quakbot
File size:9'727 bytes
First seen:2022-11-18 14:19:16 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:cKSLj50Tavgx685UIhpHKbP2KTMhS0OGYm9lWVjAvNzAWM5Evk7MgG+r5AJ:s52k785UIhp/KTMhSeYmn2jiu5EjP+rs
TLSH T123124A9B3D13ECF912B77AD1EEDA20B9DC1A29624CA210051C6FFB30421D7EA6D151DB
Reporter mikegmcg
Tags:js qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
306
Origin country :
CA CA
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Base64 Encoded URL
Detected an ANSI or UNICODE http:// or https:// base64 encoded URL prefix.
Result
Threat name:
Unknown
Detection:
clean
Classification:
n/a
Score:
1 / 100
Behaviour
Behavior Graph:
n/a
Threat name:
Script-JS.Trojan.Magniber
Status:
Malicious
First seen:
2022-11-18 14:20:06 UTC
File Type:
Text (VBS)
AV detection:
1 of 39 (2.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Quakbot

Java Script (JS) js 0ba184cdfa520fd888599a9c62cf5e7e0a5e0a74d3cd3c7067579a8b0d93acf1

(this sample)

Comments