MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 87c2c690b9a4ccd266848d48dcddec5f21472f30e1684066638c44e7f287e51f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 87c2c690b9a4ccd266848d48dcddec5f21472f30e1684066638c44e7f287e51f
SHA3-384 hash: 54457d9f701209ebc0689ed5e4b840a89db3eb145af2c72f2f3033d9c0e51d5117daa045bd6bfc134238646a4cfd275c
SHA1 hash: ee8d354ce82e46eabc3fcd66487d7872fc4bae43
MD5 hash: 29fc7d472f309a711ebd7b4250ad5ee8
humanhash: bacon-muppet-summer-seventeen
File name:RfIsDFAgCoRK.js
Download: download sample
Signature Quakbot
File size:340'555 bytes
First seen:2023-06-14 07:45:19 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 6144:bSfr0dh2tgcH6YTkM0cNRcpZwg/EBQ+8N/ygD1pRbwq2jwNxTlhS:bSfrSh2tgcH6YTkMXRcpZwg/QQ+I/ygC
TLSH T1A37431486A51E0F19237B33BCA565420FA6B1F5B2084C972B97C505D2F3D8297EB7EC8
Reporter JAMESWT_WT
Tags:js Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
291
Origin country :
IT IT
Vendor Threat Intelligence
Result
Verdict:
MALICIOUS
Threat name:
Script-JS.Trojan.Cryxos
Status:
Malicious
First seen:
2023-06-13 21:22:26 UTC
File Type:
Text (HTML)
AV detection:
6 of 36 (16.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Quakbot

Java Script (JS) js 87c2c690b9a4ccd266848d48dcddec5f21472f30e1684066638c44e7f287e51f

(this sample)

Comments