MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a977ba1c34215867748e450f5323ec6938f45e532b756f9c623e448670d0aa2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 3


Intelligence 3 IOCs YARA 5 File information Comments

SHA256 hash: a977ba1c34215867748e450f5323ec6938f45e532b756f9c623e448670d0aa2b
SHA3-384 hash: e9ef3ee2bb89525f2fe496574df444c82e2b006dd3ae1f49095f2914bdad44b4a29d57169373c3c3427105497631bcd4
SHA1 hash: 6ca37a684a3fdd882d8449be24a73a0f3853ba90
MD5 hash: 3a77a478f3edd33a05c45bf05ec1bb88
humanhash: gee-finch-juliet-salami
File name:P7.zip
Download: download sample
Signature Quakbot
File size:414'383 bytes
First seen:2022-11-21 12:34:00 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: XP11
ssdeep 12288:gabtZAOQzcHyVgp4HPtyY/GMcn8gIQ9Q3jw:gabtH0ayVgp4HP3eMlQQzw
TLSH T11694236FCCC4E0A5D1C71BAA022F1BCEB3655215A99D25F531FB9068D40CE135FB29B2
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter pr0xylife
Tags:1669024152 BB07 pw-XP11 Qakbot Quakbot zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
278
Origin country :
IE IE
File Archive Information

This file archive contains 4 file(s), sorted by their relevance:

File name:lemur.temp
File size:501'760 bytes
SHA256 hash: 3c0c4314624497645c426ed6e9fbfd37042f7aceb51e60a894135ea4a42851c0
MD5 hash: a736ea84089591e4b6ed3b4051f393d0
MIME type:application/x-dosexec
Signature Quakbot
File name:data.txt
File size:4 bytes
SHA256 hash: e5b0843f42485b22242c595fe066bb00d8ff8fe63fcbb22ca9ffe157fb57255a
MD5 hash: bc5602dd9d96a28376eeaa0e59eae06c
MIME type:text/plain
Signature Quakbot
File name:precede.png
File size:38'208 bytes
SHA256 hash: 87e5520dc4c41b79bfced2027ffed535b40986ae4a00b4d76922b97309fff246
MD5 hash: 89f11b503672c56ed1e91614daa59a9f
MIME type:image/png
Signature Quakbot
File name:JG.js
File size:10'642 bytes
SHA256 hash: 3b00174d5b42adf5da7fe896ce8baae14d67c52f79c49eed82bdf87e3a28d625
MD5 hash: 6058a64332831c510b20951ccd49e839
MIME type:text/plain
Signature Quakbot
Vendor Threat Intelligence
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:PassProtected_ZIP_ISO_file
Author:_jc
Description:Detects container formats commonly smuggled through password-protected zips
Rule name:QakBot
Author:kevoreilly
Description:QakBot Payload
Rule name:unpacked_qbot
Description:Detects unpacked or memory-dumped QBot samples
Rule name:win_qakbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.qakbot.
Rule name:win_qakbot_malped
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.qakbot.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments