🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9bfcdb28009feeda218c4322dabcc1f6464ce64fdede12c988db36889e77fa2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9bfcdb28009feeda218c4322dabcc1f6464ce64fdede12c988db36889e77fa2d
SHA3-384 hash: 5255541a75f6d395b985f813b82f75d1b3d3b0f32503b89dd483e58ef2780301d235dad6ca1a363775eecf36aeb60bdd
SHA1 hash: 6227adb5d7fd9f5d7b30b1ee51126e8c2af84f03
MD5 hash: a9a100403a4d18239c2abb3949bd6c90
humanhash: enemy-nitrogen-leopard-stairway
File name:Quia.pdf
Download: download sample
Signature Quakbot
File size:91'326 bytes
First seen:2023-04-05 12:26:13 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:8OG210Uv9PrGBML8UYY6ustjs/Om/AXJvk:tlJ9hYY6ums/x/1
TLSH T13B93F1CED486DC9CE844382AE1ECBF15825EE00F42DEE6F63B6E68CC905FD55905066D
Reporter Cryptolaemus1
Tags:1680686988 BB22 pdf Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
434
Origin country :
BE BE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
phishing remote
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
phis
Score:
48 / 100
Signature
Downloads suspicious files via Chrome
PDF lure found (based on various OCR indicators)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 841729 Sample: Quia.pdf Startdate: 05/04/2023 Architecture: WINDOWS Score: 48 37 Downloads suspicious files via Chrome 2->37 39 PDF lure found (based on various OCR indicators) 2->39 8 chrome.exe 18 8 2->8         started        12 AcroRd32.exe 15 39 2->12         started        process3 dnsIp4 33 239.255.255.250 unknown Reserved 8->33 25 C:\Users\user\Downloads\UAN.zip (copy), Zip 8->25 dropped 14 unarchiver.exe 4 8->14         started        16 chrome.exe 8->16         started        35 192.168.2.1 unknown unknown 12->35 19 RdrCEF.exe 64 12->19         started        file5 process6 dnsIp7 21 7za.exe 3 14->21         started        27 gruastranservis.com 198.54.120.44, 443, 49700 NAMECHEAP-NETUS United States 16->27 29 www.google.com 142.251.36.164, 443, 49706, 49736 GOOGLEUS United States 16->29 31 4 other IPs or domains 16->31 process8 process9 23 conhost.exe 21->23         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments