MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b338c9afc864fa9b2cda3591c494e9ac81d0a4e54161ffa966a10005c634528. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 7b338c9afc864fa9b2cda3591c494e9ac81d0a4e54161ffa966a10005c634528
SHA3-384 hash: 9af31ac90695663c220f723737c761370be1175f01b85c3d6e6b7de915d5f30faad5845ae5c8130f0c4c5ad87a7a6ec9
SHA1 hash: 323e4422e4df9606ca977a858dcd567d6ebd900c
MD5 hash: 900024080a53ea49f9f7cc6ef6a07d35
humanhash: seven-alpha-early-sad
File name:0502.gif
Download: download sample
Signature Quakbot
File size:792'432 bytes
First seen:2021-02-05 21:20:08 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash 402ce0f96b9775352c62a72ec6048452 (1 x Quakbot)
ssdeep 12288:kdPNoA46RL2SnVc1DouVvl/dmMlj8MAh9nz3AbjAx7wzB1ARWvEpPp1JPPPHKGzp:6q7gVgLs4Afz3AXRBMXh7PPPjp
Threatray 104 similar samples on MalwareBazaar
TLSH EAF48DA2B693C1BBC43DC1B1D86A9BF6BDB8DD59D29880F33BD83EEA79314444674104
Reporter unixronin
Tags:exe Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
343
Origin country :
n/a
Vendor Threat Intelligence
Malware family:
n/a
ID:
1
File name:
documentation (64).xls
Verdict:
Malicious activity
Analysis date:
2021-02-05 17:40:48 UTC
Tags:
macros qbot

Note:
ANY.RUN is an interactive sandbox that analyzes all user actions rather than an uploaded sample
Result
Verdict:
Malware
Maliciousness:

Behaviour
Searching for the window
Searching for many windows
Creating a file in the Windows subdirectories
Launching a process
Modifying an executable file
Creating a process with a hidden window
Creating a window
Sending a UDP request
Unauthorized injection to a system process
Enabling autorun by creating a file
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Backdoor.Quakbot
Status:
Malicious
First seen:
2021-02-05 17:10:03 UTC
AV detection:
19 of 29 (65.52%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:tr campaign:1612451251 banker stealer trojan
Behaviour
Checks SCSI registry key(s)
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Program crash
Loads dropped DLL
Qakbot/Qbot
Malware Config
C2 Extraction:
176.205.222.30:2078
213.60.147.140:443
45.118.216.157:443
83.110.103.152:443
108.46.145.30:443
81.150.181.168:2222
24.229.150.54:995
45.77.115.208:2222
154.125.120.87:995
50.29.166.232:995
193.252.48.200:443
67.8.103.21:443
1.32.35.2:443
85.132.36.111:2222
197.51.82.72:443
173.17.117.83:443
45.63.107.192:443
82.76.47.211:443
149.28.99.97:995
144.202.38.185:2222
149.28.98.196:2222
144.202.38.185:995
149.28.101.90:443
149.28.101.90:995
45.32.211.207:995
207.246.116.237:8443
45.63.107.192:995
45.32.211.207:2222
45.32.211.207:8443
207.246.77.75:443
207.246.116.237:995
207.246.77.75:8443
149.28.98.196:995
45.63.107.192:2222
144.202.38.185:443
149.28.98.196:443
207.246.116.237:2222
149.28.99.97:443
207.246.77.75:995
207.246.116.237:443
149.28.101.90:8443
149.28.99.97:2222
149.28.101.90:2222
45.77.115.208:443
207.246.77.75:2222
173.21.10.71:2222
45.32.211.207:443
184.189.122.72:443
201.171.77.138:443
98.121.187.78:443
98.240.24.57:443
122.148.156.131:995
77.27.174.49:995
92.59.35.196:2222
45.77.115.208:995
45.77.115.208:8443
151.205.102.42:443
172.87.157.235:3389
83.110.12.140:2222
85.58.200.50:2222
86.236.77.68:2222
2.232.253.79:995
24.50.118.93:443
176.205.222.30:2222
95.77.223.148:443
84.247.55.190:8443
86.98.93.124:2078
151.33.233.193:443
70.126.76.75:443
172.78.30.215:443
119.157.118.42:3389
89.3.198.238:443
160.3.187.114:443
106.51.85.162:443
64.121.114.87:443
23.240.70.80:443
115.69.252.0:22
197.161.154.132:443
50.244.112.106:443
83.110.108.181:2222
105.198.236.99:443
140.82.49.12:443
188.25.63.105:443
181.48.190.78:443
80.11.173.82:8443
142.68.28.22:443
72.240.200.181:2222
71.88.193.17:443
103.51.20.143:2222
156.223.228.116:995
90.101.117.122:2222
81.97.154.100:443
78.63.226.32:443
68.186.192.69:443
86.220.60.133:2222
46.153.119.255:995
154.118.28.100:3389
67.6.12.4:443
88.226.163.213:443
78.97.207.104:443
217.128.247.208:2222
86.97.162.85:443
81.88.254.62:443
216.201.162.158:443
105.186.102.16:443
68.225.60.77:995
71.187.170.235:443
144.139.47.206:443
41.39.134.183:443
97.69.160.4:2222
81.214.126.173:2222
108.31.15.10:995
96.21.251.127:2222
203.194.110.74:443
2.50.2.216:443
209.210.187.52:995
193.248.221.184:2222
75.136.40.155:443
82.127.125.209:990
24.139.72.117:443
79.129.121.81:995
67.165.206.193:993
37.211.90.175:995
24.55.112.61:443
196.151.252.84:443
84.72.35.226:443
176.181.247.197:443
109.150.80.242:443
70.168.130.172:995
89.137.211.239:995
47.22.148.6:443
106.250.150.98:443
86.98.212.242:2222
80.11.5.65:2222
59.90.246.200:443
105.198.236.101:443
2.7.69.217:2222
71.74.12.34:443
217.165.22.188:443
125.63.101.62:443
154.177.89.164:443
202.187.58.21:443
202.184.20.119:443
39.57.147.20:995
171.103.138.122:995
77.31.46.230:443
115.133.243.6:443
42.115.200.16:443
189.222.139.243:443
27.223.92.142:995
Unpacked files
SH256 hash:
7b338c9afc864fa9b2cda3591c494e9ac81d0a4e54161ffa966a10005c634528
MD5 hash:
900024080a53ea49f9f7cc6ef6a07d35
SHA1 hash:
323e4422e4df9606ca977a858dcd567d6ebd900c
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Quakbot

Executable exe 7b338c9afc864fa9b2cda3591c494e9ac81d0a4e54161ffa966a10005c634528

(this sample)

Comments