MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1afaa9ab2ee0c6e5a93b23b207295eb9c3b10d350c0bf190ea92abc0b5628837. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 1afaa9ab2ee0c6e5a93b23b207295eb9c3b10d350c0bf190ea92abc0b5628837
SHA3-384 hash: f7d01378ec390c48352ae85166cb10d2d46770c9b590d8ad8a0aa4c5185b7b22895d1ab092affa9b9b3d646ea37898dc
SHA1 hash: 691418e95d25425f4aec236d4c24ca8b933ee712
MD5 hash: f25009a3da938d1425c9acb63a221be7
humanhash: avocado-skylark-connecticut-lithium
File name:21348842916.dat
Download: download sample
Signature Quakbot
File size:505'360 bytes
First seen:2022-03-02 14:19:31 UTC
Last seen:2022-03-02 15:09:48 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 4fa27ad98716b4898b1b45c71378e3ca (20 x Quakbot)
ssdeep 12288:+zhOcpH9fCo8nI/eFUz9WXlttrllIHL75Ngb:+FpHGnITBGnAHL7P+
Threatray 112 similar samples on MalwareBazaar
TLSH T1AAB4C0B876107CF6E67F067BDA95ACD9037A26228EC798CD416477C709733A1EE12C09
Reporter pr0xylife
Tags:CLEVER CLOSE s.r.o. dll obama162 Qakbot Quakbot signed

Code Signing Certificate

Organisation:CLEVER CLOSE s.r.o.
Issuer:Sectigo Public Code Signing CA R36
Algorithm:sha384WithRSAEncryption
Valid from:2022-01-18T00:00:00Z
Valid to:2023-01-18T23:59:59Z
Serial number: da20761afbb0463c55b1ea88bbc7ec57
Intelligence: 20 malware samples on MalwareBazaar are signed with this code signing certificate
MalwareBazaar Blocklist:This certificate is on the MalwareBazaar code signing certificate blocklist (CSCB)
Thumbprint Algorithm:SHA256
Thumbprint: f12dd6e77ffab75870b24dd5bfda5a360843f9e5591e764be9f0a2ac59a710d3
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
170
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware overlay packed
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Detection:
malicious
Classification:
troj
Score:
60 / 100
Signature
Found malware configuration
Sigma detected: Suspicious Call by Ordinal
Yara detected Qbot
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 581670 Sample: 21348842916.dat Startdate: 02/03/2022 Architecture: WINDOWS Score: 60 20 store-images.s-microsoft.com 2->20 22 Found malware configuration 2->22 24 Yara detected Qbot 2->24 26 Sigma detected: Suspicious Call by Ordinal 2->26 8 loaddll32.exe 1 2->8         started        signatures3 process4 process5 10 cmd.exe 1 8->10         started        12 regsvr32.exe 8->12         started        14 rundll32.exe 8->14         started        16 2 other processes 8->16 process6 18 rundll32.exe 10->18         started       
Threat name:
Win32.Backdoor.Quakbot
Status:
Malicious
First seen:
2022-03-02 14:20:17 UTC
File Type:
PE (Dll)
AV detection:
18 of 27 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:obama162 campaign:1646211672 banker stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Qakbot/Qbot
Malware Config
C2 Extraction:
89.249.215.26:61202
136.143.11.232:443
5.88.12.21:443
82.152.39.39:443
103.139.242.30:990
144.202.2.175:995
69.14.172.24:443
118.161.12.23:995
31.215.70.101:443
39.52.44.39:995
92.177.45.46:2078
197.89.109.221:443
103.139.242.30:993
39.44.58.183:995
89.211.185.240:2222
193.253.44.249:2222
120.150.218.241:995
76.70.9.169:2222
180.233.150.134:995
220.129.52.36:443
67.209.195.198:443
75.67.194.204:443
124.41.193.166:443
217.128.122.65:2222
128.106.122.206:443
118.161.12.23:443
89.101.97.139:443
92.99.229.158:2222
32.221.231.1:443
102.156.225.86:443
2.50.37.117:443
217.165.146.156:32101
180.183.100.147:2222
80.14.188.219:2222
167.86.202.26:443
111.125.245.118:995
117.248.109.38:21
86.98.156.238:993
120.61.2.121:443
91.177.173.10:995
176.110.96.225:443
176.57.126.138:443
41.230.62.211:993
197.164.171.102:995
96.21.251.127:2222
2.50.41.69:61200
74.15.2.252:2222
182.191.92.203:995
80.11.74.81:2222
89.137.52.44:443
41.43.13.54:995
209.210.95.228:32100
63.153.150.20:443
196.203.37.215:80
190.73.3.148:2222
118.189.242.45:2083
185.249.85.209:443
63.143.92.99:995
103.230.180.119:443
160.179.163.47:443
93.48.80.198:995
41.84.236.119:443
78.100.194.138:6883
114.79.148.170:443
103.87.95.131:2222
144.202.2.175:443
176.67.56.94:443
66.230.104.103:443
47.180.172.159:443
76.25.142.196:443
140.82.49.12:443
75.99.168.194:443
202.56.44.112:993
197.167.46.225:993
47.180.172.159:50010
86.98.149.6:995
24.178.196.158:2222
76.69.155.202:2222
105.184.116.32:995
2.50.27.78:443
208.107.221.224:443
173.174.216.62:443
47.23.89.60:993
197.167.46.225:995
75.188.35.168:443
141.237.140.181:995
76.169.147.192:32103
75.99.168.194:61201
70.57.207.83:443
103.133.200.140:443
186.64.67.40:443
121.74.187.191:995
41.13.143.139:443
41.228.22.180:443
45.46.53.140:2222
188.50.5.129:995
58.105.167.35:50000
86.105.41.126:61202
86.97.247.128:1194
75.156.151.34:443
173.21.10.71:2222
102.65.38.67:443
71.74.12.34:443
189.253.111.123:995
119.158.98.225:995
191.99.191.28:443
190.189.33.6:32101
47.156.131.10:443
73.151.236.31:443
98.17.34.83:995
149.135.101.20:443
201.103.17.10:443
100.1.108.246:443
70.51.153.159:2222
72.252.201.34:995
72.252.201.34:990
208.101.87.135:443
105.224.227.30:995
108.4.67.252:443
161.142.56.218:443
38.70.253.226:2222
24.55.67.176:443
47.156.191.217:443
39.52.218.58:995
78.96.235.245:443
217.164.117.158:2222
109.12.111.14:443
41.84.229.223:995
5.95.58.211:2087
39.49.114.202:995
80.123.141.226:443
176.88.238.122:995
151.69.0.8:995
184.100.174.73:443
183.82.103.213:443
82.41.63.217:443
81.229.130.188:443
43.252.72.97:2222
115.69.247.95:443
67.165.206.193:993
118.189.242.45:2222
108.16.33.18:443
86.198.170.170:2222
68.204.7.158:443
84.241.8.23:32103
78.191.34.56:995
121.7.223.188:2222
218.111.147.237:443
86.139.33.187:443
Unpacked files
SH256 hash:
2425fc097fe82eab70b1c0dc89468062801b90b0de06db5055acfe420f9ee254
MD5 hash:
22be6063398e70dcf33497b8bee64794
SHA1 hash:
8a42e3dec5005823305c7642020016782c19be5d
SH256 hash:
1afaa9ab2ee0c6e5a93b23b207295eb9c3b10d350c0bf190ea92abc0b5628837
MD5 hash:
f25009a3da938d1425c9acb63a221be7
SHA1 hash:
691418e95d25425f4aec236d4c24ca8b933ee712
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments