🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 91e43c044fdcad13a25d772b91065f78ac7a809a57ace84a4606c4c3e92afaa2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



BumbleBee


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 91e43c044fdcad13a25d772b91065f78ac7a809a57ace84a4606c4c3e92afaa2
SHA3-384 hash: c41ffa73c20b2d33a540b3bfa66c7b49d4ded37ff5b445b5e7abb9eb51bc3d6fe9ba2a67f72b2f72ab17324546cca5a1
SHA1 hash: 2442ca895275f9a4bda44c18273ad6b8d6815780
MD5 hash: 323ee7e3d79671befe72fe6f79f0f6b3
humanhash: hydrogen-beer-muppet-tennis
File name:Contract_02_21_Copy#101.pdf
Download: download sample
Signature BumbleBee
File size:104'543 bytes
First seen:2023-02-21 21:49:29 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:0vxQOx1paEAUHpWKOUuH7v+B1tGRnr/spRre0pRI3dz+3WTzuS1/GJJ5zUpxc8+q:01J97O7v+B1tGRr/KRy3x+3z7H8AK
TLSH T12AA3026AC9858549E9DC0C70FC3E2EDDF972B179CA5A76A4365DAED38308F76F401012
Reporter proxylife
Tags:BUMBLEBEE pdf

Intelligence


File Origin
# of uploads :
1
# of downloads :
472
Origin country :
RU RU
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
2%
Score Benign:
98%
Result
Threat name:
Qbot Downloader
Detection:
malicious
Classification:
spre.troj
Score:
52 / 100
Signature
C2 URLs / IPs found in malware configuration
Yara detected Qbot Downloader
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 812953 Sample: Contract_02_21_Copy#101.pdf Startdate: 21/02/2023 Architecture: WINDOWS Score: 52 38 Yara detected Qbot Downloader 2->38 40 C2 URLs / IPs found in malware configuration 2->40 8 chrome.exe 18 8 2->8         started        11 AcroRd32.exe 15 39 2->11         started        13 chrome.exe 2->13         started        process3 dnsIp4 34 192.168.2.5 unknown unknown 8->34 36 239.255.255.250 unknown Reserved 8->36 15 unarchiver.exe 4 8->15         started        17 chrome.exe 8->17         started        20 RdrCEF.exe 74 11->20         started        process5 dnsIp6 22 7za.exe 2 15->22         started        26 www.google.com 142.250.180.132, 443, 49703, 49718 GOOGLEUS United States 17->26 28 clients.l.google.com 142.250.180.174, 443, 49700 GOOGLEUS United States 17->28 32 3 other IPs or domains 17->32 30 192.168.2.1 unknown unknown 20->30 process7 process8 24 conhost.exe 22->24         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments