MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0ab609747b185b820ed3a65ba00934adebd2d12689d4a49c21094ac870ff0f4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a0ab609747b185b820ed3a65ba00934adebd2d12689d4a49c21094ac870ff0f4
SHA3-384 hash: e97527bb80069c8a1af978c42623f4cef79136f9f238919c7097901e5697eaaa35c47b2a47218cf402e18781f3cb463b
SHA1 hash: dee8406d77ccdb99e8675aa534f73f058116f8fb
MD5 hash: ecbdef6c8ff15f14f034a8c4193d9dce
humanhash: earth-washington-oxygen-iowa
File name:08142020_1955816493.zip
Download: download sample
Signature Quakbot
File size:383'338 bytes
First seen:2020-08-14 18:00:08 UTC
Last seen:Never
File type: zip
MIME type:application/zip
ssdeep 6144:NfG3oKMUsTl8nLLxk8UYzBaEsD7pMJDAm3yW7L6etfduuMMCglmoyKTHSmij/V+Z:dGUhALxTUiuDQvD31eVkFy2ymibH8qK1
TLSH B784238BF9807F766DED1A8283744A20BA0CF85D6E6888EB79C140D63AC5755BD0F49C
Reporter abuse_ch
Tags:Qakbot qbot Quakbot spx155 zip


Avatar
abuse_ch
Malspam distributing Quakbot:

HELO: mout-xforward.perfora.net
Sending IP: 82.165.159.133
Subject: Re: Termination of E-mail victim-email Processed Verify Now.
Attachment: 08142020_1955816493.zip (contains "08142020_1955816493.doc")

Quakbot payload URLs:
http://bronco.is/pdniovzkgwwt/111111.png
http://craniotylla.ch/vzufnt/111111.png
http://forum.insteon.com/suowb/111111.png
http://marineworks.eu/dwaunrsamlbq/111111.png
http://nanfeiqiaowang.com/tsxwe/111111.png
http://quickinsolutions.com/wfqggeott/111111.png
http://quoraforum.com/btmlxjxmyxb/111111.png
http://rijschoolfastandserious.nl/rprmloaw/111111.png
http://studiomascellaro.it/wnzzsbzbd/111111.png
http://webtest.pp.ua/yksrpucvx/111111.png

Intelligence


File Origin
# of uploads :
1
# of downloads :
376
Origin country :
n/a
Vendor Threat Intelligence
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Quakbot

zip a0ab609747b185b820ed3a65ba00934adebd2d12689d4a49c21094ac870ff0f4

(this sample)

  
Dropping
Quakbot
  
Delivery method
Distributed via e-mail attachment

Comments