MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Quakbot
Vendor detections: 7
| SHA256 hash: | 627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664 |
|---|---|
| SHA3-384 hash: | 44f98209c12a76202ebe0d3b0e02228e1619aca706ae31eec1fcb0f7161c03302120bd56bbe7d7050fe2b643c05509da |
| SHA1 hash: | 1f0e969f588aea75194985dd6dc031f5afef388e |
| MD5 hash: | c3bc8d416a027239200dec2d50c28539 |
| humanhash: | muppet-whiskey-robin-kansas |
| File name: | 44313,6048108796.dat |
| Download: | download sample |
| Signature | Quakbot |
| File size: | 396'816 bytes |
| First seen: | 2021-04-30 16:30:02 UTC |
| Last seen: | 2021-04-30 18:03:52 UTC |
| File type: | |
| MIME type: | application/x-dosexec |
| imphash | 3e1f0fb4b54229dd240a1006f34727b8 (3 x Quakbot) |
| ssdeep | 6144:oWHgRUTixuu8njF/EeBfCFH7OE11J8JRO+njE2X2J/7vKsaG:oWYNuu8njF/EqfCFHyY1+lFGl |
| Threatray | 1'355 similar samples on MalwareBazaar |
| TLSH | 4B84BF7DAA22C877E2152FF162D35F980913A8F47660664F51B12F1E2EAD3C47C3AE44 |
| Reporter | |
| Tags: | Qakbot Quakbot |
Intelligence
File Origin
# of uploads :
2
# of downloads :
141
Origin country :
n/a
Vendor Threat Intelligence
Detection:
QakBot
Detection(s):
Result
Verdict:
Clean
Maliciousness:
Behaviour
Sending a UDP request
Launching a process
Creating a process with a hidden window
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Packed.Generic
Status:
Suspicious
First seen:
2021-04-30 16:30:19 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
1/5
Detection(s):
Suspicious file
Verdict:
malicious
Label(s):
qakbot
Similar samples:
+ 1'345 additional samples on MalwareBazaar
Unpacked files
SH256 hash:
bdfa467549608b3447c749d2465d8db91a35ef3f9d51bc668677dcd6bf91cf0e
MD5 hash:
3303a3d18581df3af7e83c8291f16395
SHA1 hash:
848f49a2fc975b397040f13430a39d8a3bf723c8
Detections:
win_qakbot_auto
SH256 hash:
627ff5c6fcd538aa53d68149ab497f233ac741b1930acee12d9f549453cce664
MD5 hash:
c3bc8d416a027239200dec2d50c28539
SHA1 hash:
1f0e969f588aea75194985dd6dc031f5afef388e
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Qakbot
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.