MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664
SHA3-384 hash: 44f98209c12a76202ebe0d3b0e02228e1619aca706ae31eec1fcb0f7161c03302120bd56bbe7d7050fe2b643c05509da
SHA1 hash: 1f0e969f588aea75194985dd6dc031f5afef388e
MD5 hash: c3bc8d416a027239200dec2d50c28539
humanhash: muppet-whiskey-robin-kansas
File name:44313,6048108796.dat
Download: download sample
Signature Quakbot
File size:396'816 bytes
First seen:2021-04-30 16:30:02 UTC
Last seen:2021-04-30 18:03:52 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 3e1f0fb4b54229dd240a1006f34727b8 (3 x Quakbot)
ssdeep 6144:oWHgRUTixuu8njF/EeBfCFH7OE11J8JRO+njE2X2J/7vKsaG:oWYNuu8njF/EqfCFHyY1+lFGl
Threatray 1'355 similar samples on MalwareBazaar
TLSH 4B84BF7DAA22C877E2152FF162D35F980913A8F47660664F51B12F1E2EAD3C47C3AE44
Reporter JasonMilletary
Tags:Qakbot Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Launching a process
Creating a process with a hidden window
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2021-04-30 16:30:19 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Unpacked files
SH256 hash:
bdfa467549608b3447c749d2465d8db91a35ef3f9d51bc668677dcd6bf91cf0e
MD5 hash:
3303a3d18581df3af7e83c8291f16395
SHA1 hash:
848f49a2fc975b397040f13430a39d8a3bf723c8
Detections:
win_qakbot_auto
SH256 hash:
627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664
MD5 hash:
c3bc8d416a027239200dec2d50c28539
SHA1 hash:
1f0e969f588aea75194985dd6dc031f5afef388e
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments