MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 abe2930c83d646ca388b1bf050de6c84228069fd77e0f15de06f14b25f213427. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 11


Intelligence 11 IOCs YARA 5 File information Comments

SHA256 hash: abe2930c83d646ca388b1bf050de6c84228069fd77e0f15de06f14b25f213427
SHA3-384 hash: c08d779ea21d12de37c7aef934aae6dcde2df01868581d715f6e92322c26903ff36c246af78876a86a2980e991f5a24b
SHA1 hash: 28057bf80100b7e55283e746c98c0a1d87822cc1
MD5 hash: ff3dc8073a39c78624b84d9e93da1d24
humanhash: avocado-emma-august-fillet
File name:lDdHe.dll
Download: download sample
Signature Quakbot
File size:745'984 bytes
First seen:2022-11-14 16:05:17 UTC
Last seen:2022-11-14 17:45:34 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash ca63142394e1cc02b89c5720b23d755b (2 x Quakbot)
ssdeep 12288:m5jtYFL7M09nF9u/2OvyStn2lsBdfKa5GFLE2p21wjj4ptJ3NdHj6HGc:m5jtYFL7MgnF9u/TvySVisB8PLVp723b
TLSH T132F4178BF8CAEF4AC63F467CD19E43114E6B8A804F125B83621D17B230536195FA77AD
TrID 32.2% (.EXE) Win64 Executable (generic) (10523/12/4)
20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2)
15.4% (.EXE) Win16 NE executable (generic) (5038/12/1)
13.7% (.EXE) Win32 Executable (generic) (4505/5/1)
6.2% (.EXE) OS/2 Executable (generic) (2029/13)
Reporter pr0xylife
Tags:1668419671 BB06 dll Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
217
Origin country :
IE IE
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Сreating synchronization primitives
Launching a process
Searching for synchronization primitives
Modifying an executable file
Creating a window
Unauthorized injection to a system process
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
greyware
Result
Verdict:
UNKNOWN
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.KBot
Status:
Malicious
First seen:
2022-11-14 16:06:08 UTC
File Type:
PE (Dll)
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Verdict:
malicious
Label(s):
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:bb06 campaign:1668419671 banker stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Qakbot/Qbot
Malware Config
C2 Extraction:
64.207.237.118:443
89.240.102.164:995
190.18.236.175:443
85.241.180.94:443
92.24.200.226:995
82.127.174.33:2222
24.228.132.224:2222
175.205.2.54:443
197.1.200.71:995
93.164.248.234:443
174.101.111.4:443
37.14.229.220:2222
24.142.218.202:443
152.170.17.136:443
90.104.22.28:2222
24.64.114.59:61202
86.225.214.138:2222
92.27.86.48:2222
70.120.228.205:2083
24.206.27.39:443
27.99.45.237:2222
105.103.27.80:32103
170.253.25.35:443
24.64.114.59:2222
92.207.132.174:2222
86.133.237.3:443
172.117.139.142:995
108.6.249.139:443
92.239.81.124:443
86.129.13.128:2222
47.34.30.133:443
86.148.55.111:443
94.63.65.146:443
24.64.114.59:3389
184.153.132.82:443
74.66.134.24:443
83.11.84.105:2222
105.184.161.242:443
82.121.237.106:2222
112.141.184.246:995
91.165.188.74:50000
91.180.68.95:2222
188.4.196.132:995
88.171.156.150:50000
83.7.56.214:443
75.99.125.238:2222
105.103.27.80:990
62.35.67.88:443
105.103.27.80:2078
62.31.130.138:465
87.220.205.14:2222
193.3.19.137:443
73.36.196.11:443
24.116.45.121:443
2.84.98.228:2222
50.68.204.71:443
85.59.61.52:2222
58.247.115.126:995
180.151.104.143:443
212.251.122.147:995
100.16.107.117:443
24.49.232.96:443
174.77.209.5:443
157.231.42.190:443
73.165.119.20:443
213.91.235.146:443
87.223.88.205:443
90.221.5.105:443
50.68.204.71:995
79.37.204.67:443
98.145.23.67:443
86.171.75.63:443
76.68.34.167:2222
41.109.78.231:995
24.49.232.96:995
93.24.192.142:20
186.188.80.154:443
89.129.109.27:2222
213.67.255.57:2222
92.185.204.18:2078
92.137.74.174:2222
78.69.251.252:2222
190.24.45.24:995
92.106.70.62:2222
109.11.175.42:2222
24.28.121.122:443
78.253.154.211:50000
81.111.108.123:443
78.92.133.215:443
76.127.192.23:443
149.126.159.224:443
77.126.81.208:443
105.103.27.80:22
81.159.252.167:2222
94.60.141.48:995
75.143.236.149:443
110.4.255.247:443
170.249.59.153:443
75.98.154.19:443
173.239.94.212:443
176.142.207.63:443
87.202.101.164:50000
151.32.168.124:443
74.92.243.113:50000
31.190.68.212:443
85.74.158.150:2222
24.64.114.59:2078
69.133.162.35:443
84.35.26.14:995
174.104.184.149:443
136.232.184.134:995
68.47.128.161:443
50.68.204.71:993
87.65.160.87:995
200.233.108.153:995
206.1.223.209:2087
109.152.70.207:50000
174.45.15.123:443
81.229.117.95:2222
47.41.154.250:443
Unpacked files
SH256 hash:
3251dbe1ae27c6996ee4807c76bc11f71a8f83bb67b0123da9024718c582727b
MD5 hash:
8c9b9f2bbeebfa5436071ef9a095c348
SHA1 hash:
9f9018f2f906e0867cb868809f71501d806f97e2
SH256 hash:
f28f66eb12775522ac468c4711eb3dade14962bad7a94ce87bca5983db417b45
MD5 hash:
94d72f0ce7cbe37ee39e67188040b3cb
SHA1 hash:
e16ffbce9852a01d6180f6068c4366733761a520
Detections:
Qakbot win_qakbot_auto
SH256 hash:
abe2930c83d646ca388b1bf050de6c84228069fd77e0f15de06f14b25f213427
MD5 hash:
ff3dc8073a39c78624b84d9e93da1d24
SHA1 hash:
28057bf80100b7e55283e746c98c0a1d87822cc1
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:bumblebee_win_generic
Author:_kphi
Rule name:QakBot
Author:kevoreilly
Description:QakBot Payload
Rule name:unpacked_qbot
Description:Detects unpacked or memory-dumped QBot samples
Rule name:win_qakbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.qakbot.
Rule name:win_qakbot_malped
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects win.qakbot.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments