🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a0db4942b01135f86a637cff90a88334b57755360706ebcef7f2c19b85c5912. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 9a0db4942b01135f86a637cff90a88334b57755360706ebcef7f2c19b85c5912
SHA3-384 hash: 7577ac06a1be3dcbb214ed226f886016664136d0d6940d987e91fd4fc50bba18fd0559970bd309d4ad1014ebd4ec39ad
SHA1 hash: 9b8973171a3ab23de74001a32499c6e46880388d
MD5 hash: 2d1014e80be261169992a62239d9bb72
humanhash: speaker-mockingbird-wisconsin-artist
File name:B025.zip
Download: download sample
Signature Quakbot
File size:17'146 bytes
First seen:2023-05-02 17:41:02 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 384:T0RmOTzitLtIMjJC6ZjTRwUV+0nw3NijL+vRWO1+EkvlHJMv:1AzgLtIMFC6Zjaaj+vRWO1WHJu
TLSH T1D472E1B415FF216CCAEB423FA9EBB3C801A7E0BD020FFC5854889A0A4C779749076047
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter rmceoin
Tags:Qakbot Quakbot zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
582
Origin country :
US US
File Archive Information

This file archive contains 1 file(s), sorted by their relevance:

File name:B025.wsf
File size:39'661 bytes
SHA256 hash: d4f5863a20494d090fa8712ca62afc471b06d4b55c1a3916964c5eca2cffad5d
MD5 hash: 697de322b2bb984132bc6022c754ab57
MIME type:text/plain
Signature Quakbot
Vendor Threat Intelligence
Threat name:
Script-JS.Backdoor.Quakbot
Status:
Malicious
First seen:
2023-05-02 17:42:06 UTC
File Type:
Binary (Archive)
Extracted files:
4
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
n/a
Behaviour
Blocklisted process makes network request
Process spawned unexpected child process
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:QbotStuff
Author:anonymous
Rule name:SUSP_OneNote
Author:spatronn
Description:Hard-Detect One

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Quakbot

zip 9a0db4942b01135f86a637cff90a88334b57755360706ebcef7f2c19b85c5912

(this sample)

Comments