MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 541fc32b79d9f144db3d670967676bafaf306f25067ceb98ed2a3c7ef48bc7f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 541fc32b79d9f144db3d670967676bafaf306f25067ceb98ed2a3c7ef48bc7f4
SHA3-384 hash: 4ac75616c681bc578bcc20128c35886959deab6dfafc99b08872726c61afe728424c9ed86ce54bdf57dc6496ba85df5c
SHA1 hash: d703ecc2319d6b01f369ac727b9db2d2dd16a857
MD5 hash: 4453b84610b1acd1acfa681cb77b744e
humanhash: queen-four-tennis-sixteen
File name:14449.dat
Download: download sample
Signature Quakbot
File size:716'800 bytes
First seen:2023-01-31 17:55:52 UTC
Last seen:Never
File type:DLL dll
MIME type:application/x-dosexec
imphash 48ee4c9fac8d1206bb74064becdbc1dc (7 x Quakbot)
ssdeep 12288:4qwFxm3G6H4RyuHbR1MxnuTV/iV1Sd/NzQNfy:lwFxm3G6H4IuHbR1MxnuTV/iV1QmNf
TLSH T1CBE44CE4FECBE1D1F4071CBC02AA253B59BB13185838BB3AD4117E19D821286AD67F75
TrID 37.8% (.EXE) Win32 Executable MS Visual C++ (generic) (31206/45/13)
20.0% (.EXE) Microsoft Visual C++ compiled executable (generic) (16529/12/5)
12.7% (.EXE) Win64 Executable (generic) (10523/12/4)
7.9% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
6.1% (.EXE) Win16 NE executable (generic) (5038/12/1)
Reporter pr0xylife
Tags:dll obama234 Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
222
Origin country :
US US
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a custom TCP request
Verdict:
No Threat
Threat level:
  2/10
Confidence:
100%
Tags:
greyware packed rat
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
48 / 100
Signature
Sigma detected: Execute DLL with spoofed extension
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 795404 Sample: 14449.dat.dll Startdate: 31/01/2023 Architecture: WINDOWS Score: 48 37 Sigma detected: Execute DLL with spoofed extension 2->37 8 loaddll32.exe 1 2->8         started        process3 process4 10 cmd.exe 1 8->10         started        12 rundll32.exe 8->12         started        14 rundll32.exe 8->14         started        16 7 other processes 8->16 process5 18 rundll32.exe 10->18         started        20 WerFault.exe 4 9 12->20         started        23 WerFault.exe 9 14->23         started        25 WerFault.exe 9 16->25         started        27 WerFault.exe 9 16->27         started        29 WerFault.exe 16->29         started        31 2 other processes 16->31 dnsIp6 33 WerFault.exe 26 10 18->33         started        35 192.168.2.1 unknown unknown 20->35 process7
Threat name:
Win32.Backdoor.Quakbot
Status:
Malicious
First seen:
2023-01-31 17:56:08 UTC
File Type:
PE (Dll)
AV detection:
13 of 26 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Program crash
Unpacked files
SH256 hash:
541fc32b79d9f144db3d670967676bafaf306f25067ceb98ed2a3c7ef48bc7f4
MD5 hash:
4453b84610b1acd1acfa681cb77b744e
SHA1 hash:
d703ecc2319d6b01f369ac727b9db2d2dd16a857
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments