MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b0deea498617139a91f4fa0c43645268d0cdb0e5e7c19f31957c4708b7675875. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b0deea498617139a91f4fa0c43645268d0cdb0e5e7c19f31957c4708b7675875
SHA3-384 hash: c52eacd5832bd7202c2b1f710c3d57df50398a598318c8fb238363fadc5e306891b32b93b37e8e08c59e863b15ab62cf
SHA1 hash: c5d8530883a26074eea3bcaee046930710b70c53
MD5 hash: c6c69d731f0d8972ad9c949054fe3a61
humanhash: stream-missouri-saturn-hawaii
File name:docu_DF631_Jun_14_3.js
Download: download sample
Signature Quakbot
File size:22'991 bytes
First seen:2023-06-14 13:54:51 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 384:IlxwNHnWmEwxhJyyzgZT7yOjOt4kmtd70Sft:IlxwtWpwM9yV2d
TLSH T12FA298A45E8E50B98636B82594CFDD63DFE2C62D021E15CEA7099F32B11785CD0B26F8
Reporter JAMESWT_WT
Tags:1686735623 BB32 js Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
347
Origin country :
IT IT
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
sload
Result
Verdict:
UNKNOWN
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2023-06-14 13:55:00 UTC
File Type:
Text (JavaScript)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  8/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Blocklisted process makes network request
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments