MalwareBazaar Database
You are currently viewing the MalwareBazaar entry for SHA256 a0ab609747b185b820ed3a65ba00934adebd2d12689d4a49c21094ac870ff0f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.
Database Entry
Quakbot
Vendor detections: 3
| SHA256 hash: | a0ab609747b185b820ed3a65ba00934adebd2d12689d4a49c21094ac870ff0f4 |
|---|---|
| SHA3-384 hash: | e97527bb80069c8a1af978c42623f4cef79136f9f238919c7097901e5697eaaa35c47b2a47218cf402e18781f3cb463b |
| SHA1 hash: | dee8406d77ccdb99e8675aa534f73f058116f8fb |
| MD5 hash: | ecbdef6c8ff15f14f034a8c4193d9dce |
| humanhash: | earth-washington-oxygen-iowa |
| File name: | 08142020_1955816493.zip |
| Download: | download sample |
| Signature | Quakbot |
| File size: | 383'338 bytes |
| First seen: | 2020-08-14 18:00:08 UTC |
| Last seen: | Never |
| File type: | zip |
| MIME type: | application/zip |
| ssdeep | 6144:NfG3oKMUsTl8nLLxk8UYzBaEsD7pMJDAm3yW7L6etfduuMMCglmoyKTHSmij/V+Z:dGUhALxTUiuDQvD31eVkFy2ymibH8qK1 |
| TLSH | B784238BF9807F766DED1A8283744A20BA0CF85D6E6888EB79C140D63AC5755BD0F49C |
| Reporter | |
| Tags: | Qakbot qbot Quakbot spx155 zip |
abuse_ch
Malspam distributing Quakbot:HELO: mout-xforward.perfora.net
Sending IP: 82.165.159.133
Subject: Re: Termination of E-mail victim-email Processed Verify Now.
Attachment: 08142020_1955816493.zip (contains "08142020_1955816493.doc")
Quakbot payload URLs:
http://bronco.is/pdniovzkgwwt/111111.png
http://craniotylla.ch/vzufnt/111111.png
http://forum.insteon.com/suowb/111111.png
http://marineworks.eu/dwaunrsamlbq/111111.png
http://nanfeiqiaowang.com/tsxwe/111111.png
http://quickinsolutions.com/wfqggeott/111111.png
http://quoraforum.com/btmlxjxmyxb/111111.png
http://rijschoolfastandserious.nl/rprmloaw/111111.png
http://studiomascellaro.it/wnzzsbzbd/111111.png
http://webtest.pp.ua/yksrpucvx/111111.png
Intelligence
File Origin
# of uploads :
1
# of downloads :
376
Origin country :
n/a
Vendor Threat Intelligence
Detection(s):
Malicious file
Please note that we are no longer able to provide a coverage score for Virus Total.
Threat name:
Malicious File
Score:
1.00
File information
The table below shows additional information about this malware sample such as delivery method and external references.
Malspam
Dropping
Quakbot
Delivery method
Distributed via e-mail attachment
Comments
Login required
You need to login to in order to write a comment. Login with your abuse.ch account.