MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5cfd15470a434f048d29051ce733cae8063479d706e2b6156d4dfaddef386894. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 5cfd15470a434f048d29051ce733cae8063479d706e2b6156d4dfaddef386894
SHA3-384 hash: 7372bc5c467f3b0139a1365f960ef8927051dc8a3613aea68a6c4d545bb916e7cc2fb3cb1f2764b5c40c719b25a8913d
SHA1 hash: 3f370669678269d2f55540763b1ff11ef518938b
MD5 hash: e30c4da20ba3ffed3a415be65b0cd2af
humanhash: washington-football-tennessee-connecticut
File name:byiKCv7U.zip
Download: download sample
File size:146'154 bytes
First seen:2020-08-03 20:05:07 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 1536:1YSkZDPeUYW16i0O49Ibxk/5dev70sfnZ02WQdpuf5+H40STUYsY2g:1VkZDPR6i0gNTYsfnZdVox+YN4YJV
TLSH 44E3124D838814C3F26BF773EA855997F019EA58FD01E8C7A8D5D5588EB301A73618F1
Reporter malware_traffic
Tags:Qakbot spx147 vbs zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
245
Origin country :
n/a
Vendor Threat Intelligence
Threat name:
Script-VBS.Backdoor.Quakbot
Status:
Malicious
First seen:
2020-08-03 20:07:05 UTC
File Type:
Binary (Archive)
Extracted files:
1
AV detection:
28 of 48 (58.33%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

zip 5cfd15470a434f048d29051ce733cae8063479d706e2b6156d4dfaddef386894

(this sample)

  
Delivery method
Distributed via web download

Comments