MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b8677f5a420226e9ecaf5d270cd28e26cf7482eb46256ec8455b3e6825d07f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 3b8677f5a420226e9ecaf5d270cd28e26cf7482eb46256ec8455b3e6825d07f1
SHA3-384 hash: acb46d213a1f4d482f31c25b31a227019b43530683473acf6bada49a44333db357c21e991c29a1e8deee765b1c3133b1
SHA1 hash: ba81175655f6eb31723da12ec3305e2cb4a493d2
MD5 hash: 3a1248f8fe62722573eb0eef49d47ca7
humanhash: winter-alpha-monkey-pasta
File name:3a1248f8fe62722573eb0eef49d47ca7.dll
Download: download sample
Signature Quakbot
File size:1'982'086 bytes
First seen:2021-02-23 17:24:33 UTC
Last seen:2021-02-23 19:04:00 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash 9527ec83e065e31d95ef7014093b33cc (3 x Quakbot)
ssdeep 49152:PzcJdWxK4UVuSj7AKHWv/wHwEWtHqStTWNurykBGVXCS+g99lQ:ZxlUUHK2vY/WtHbykkwG9e
Threatray 1 similar samples on MalwareBazaar
TLSH 91952389A240378DC52CC135C2736D59F7B6606F0D919634B2C7F992BB6FD0A8781F8A
Reporter abuse_ch
Tags:dll Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
376
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win64.Backdoor.Quakbot
Status:
Malicious
First seen:
2021-02-23 17:25:08 UTC
AV detection:
10 of 28 (35.71%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
3b8677f5a420226e9ecaf5d270cd28e26cf7482eb46256ec8455b3e6825d07f1
MD5 hash:
3a1248f8fe62722573eb0eef49d47ca7
SHA1 hash:
ba81175655f6eb31723da12ec3305e2cb4a493d2
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Quakbot

Executable exe 3b8677f5a420226e9ecaf5d270cd28e26cf7482eb46256ec8455b3e6825d07f1

(this sample)

  
Delivery method
Distributed via web download

Comments