MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b6942601eb28b9a6c168f162eab73bbe9c61d77a2228da5805fd54946ec4ab81. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry


Intelligence File information Yara 1 Comments

SHA256 hash: b6942601eb28b9a6c168f162eab73bbe9c61d77a2228da5805fd54946ec4ab81
SHA1 hash: cebfff507d7b47a85d6996beae85bd2b9b30a218
MD5 hash: 190848fe8ab8292e9cca65040dc388a1
File name:SecuriteInfo.com.Troj.Qbot-FS.9879.1667
Download: download sample
Signature Quakbot
File size:687'104 bytes
First seen:2020-05-22 17:45:00 UTC
Last seen:Never
File type:Executable exe
MIME type:application/x-dosexec
imphash af11ab1131393f515172b39bc638d00c
ssdeep 6144:bi8I6NWua+981ga1GmWtLDba7SfL+o4Pz5ETxX:+/4VaYaoe7STU
TLSH 30E4E017E5AF9FABFDC3727591AEF8724202DE9DC23BE4661911B068F0A51D30836B41
Reporter @SecuriteInfoCom
Tags:Quakbot

Intelligence


Mail intelligence No data
# of uploads 1
# of downloads 29
Origin country US US
ClamAV SecuriteInfo.com.Troj.Qbot-FS.9879.1667.UNOFFICIAL
VirusTotal:Virustotal results 27.78%
ReversingLabs :No data

Yara Signatures


Rule name:win_qakbot_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:autogenerated rule brought to you by yara-signator

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments