MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2cfcbec026bb16339c4e07f1248afa994338320e78478d4ed75291d570f39509. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara 1 Comments

SHA256 hash: 2cfcbec026bb16339c4e07f1248afa994338320e78478d4ed75291d570f39509
SHA1 hash: aaa38e3ebc21c22a9b7cae09e10439a8cd8aefae
MD5 hash: c18073cf7da7fa1bdd2d10ea133c1bb0
File name:SecuriteInfo.com.Troj.Qbot-FS.13897.7991
Download: download sample
Signature Quakbot
File size:686'592 bytes
First seen:2020-05-22 22:40:35 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 0abf8e733820b5003a4e83f051a63d7a
ssdeep 6144:yi8I6NWua+981ga1GmWtLDba7SfL+o8Pz5ETxX:p/4VaYaoe7STI
TLSH D5E4E057E5AF9F6BFDC3727591AEF8724602DE8DC23BE4221911B068F0A51D3093AB41
Reporter @SecuriteInfoCom
Tags:Quakbot

Intelligence


Mail intelligence No data
# of uploads 1
# of downloads 27
Origin country FR FR
ClamAV SecuriteInfo.com.Troj.Qbot-FS.13897.7991.UNOFFICIAL
VirusTotal:Virustotal results 28.77%
ReversingLabs :No data

Yara Signatures


Rule name:win_qakbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments