MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c94a7e8ffd221e0d563d8ccc9252b70cea56388ebd9b4441f9a728fa4020507. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: 2c94a7e8ffd221e0d563d8ccc9252b70cea56388ebd9b4441f9a728fa4020507
SHA3-384 hash: bec4713571b35e254ded67fb85147166e0a41081237da0faed880d2922eee09b58d7ae4ca4303533ef6dcee67e21fdc9
SHA1 hash: b29e99c178674313e26972532f3ae2f04bd16ffb
MD5 hash: ba32b14fc8f6bd105a5b26e82aa07929
humanhash: bulldog-beryllium-fanta-tennis
File name:ba32b14fc8f6bd105a5b26e82aa07929.dll
Download: download sample
Signature Quakbot
File size:762'846 bytes
First seen:2021-04-12 18:44:02 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 12288:LAlF6Uoww/SY6TB0bbg3dW3JHrvVDPjjqXtBIV0Q5VFRObAB76gH:LAboz/I6budWhdq9EROsB3H
TLSH E1F45B36F1D3C437D5333A7CCE5B91A9A827BE511D28A45A7AE40D088F3E6813D2D2D6
Reporter abuse_ch
Tags:dll Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
237
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Verdict:
suspicious
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
2c94a7e8ffd221e0d563d8ccc9252b70cea56388ebd9b4441f9a728fa4020507
MD5 hash:
ba32b14fc8f6bd105a5b26e82aa07929
SHA1 hash:
b29e99c178674313e26972532f3ae2f04bd16ffb
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Quakbot

DLL dll 2c94a7e8ffd221e0d563d8ccc9252b70cea56388ebd9b4441f9a728fa4020507

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-04-14 15:35:47 UTC

============================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
============================================================
0) [B0001.025] Anti-Behavioral Analysis::Software Breakpoints
1) [C0019] Data Micro-objective::Check String
2) [C0026.002] Data Micro-objective::XOR::Encode Data