🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bebf0dbfc471717f27ff0a0ecbd591efdcdc6ed84e92380ef98284785c0e5750. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: bebf0dbfc471717f27ff0a0ecbd591efdcdc6ed84e92380ef98284785c0e5750
SHA3-384 hash: 796e45c2adaff2864d04d37c70cb1c78910973d150df2d5ab5279818c750168eadcc35f63e394c2c122244d1ae2ea77d
SHA1 hash: 72205dfacbef24a74f9be749bfa79f98a1b4cbd7
MD5 hash: ba049609fcc9b473cfb00a21fda46a3c
humanhash: arizona-romeo-helium-spring
File name:Voluptatem.pdf
Download: download sample
Signature Quakbot
File size:91'831 bytes
First seen:2023-04-06 10:39:40 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:oiGzD+kOIJZ1hlw1cfXppt/Et51miA3TUJuERGXJC/kIz6gB+2lx0iIY+sBqocry:jGWkTJ7KqOtT4EMIzTpHmcj0KEA
TLSH T16C93F151A068A46DE806B77AD045FF65072F740310C6FB3F61912CCDE08DAA0E666BFE
Reporter proxylife
Tags:1680772777 BB22 pdf Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
497
Origin country :
RU RU
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
phishing remote
Label:
Benign
Suspicious Score:
1.6/10
Score Malicious:
17%
Score Benign:
83%
Result
Threat name:
Unknown
Detection:
malicious
Classification:
phis
Score:
64 / 100
Signature
Antivirus detection for URL or domain
Downloads suspicious files via Chrome
Multi AV Scanner detection for submitted file
PDF lure found (based on various OCR indicators)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 842501 Sample: Voluptatem.pdf Startdate: 06/04/2023 Architecture: WINDOWS Score: 64 39 Antivirus detection for URL or domain 2->39 41 Multi AV Scanner detection for submitted file 2->41 43 Downloads suspicious files via Chrome 2->43 45 PDF lure found (based on various OCR indicators) 2->45 8 chrome.exe 19 8 2->8         started        12 AcroRd32.exe 15 39 2->12         started        process3 dnsIp4 35 192.168.2.6 unknown unknown 8->35 37 239.255.255.250 unknown Reserved 8->37 25 C:\Users\user\Downloads\Ju.zip (copy), Zip 8->25 dropped 14 unarchiver.exe 4 8->14         started        16 chrome.exe 8->16         started        19 RdrCEF.exe 73 12->19         started        file5 process6 dnsIp7 21 7za.exe 3 14->21         started        27 www.google.com 142.251.36.164, 443, 49704, 49738 GOOGLEUS United States 16->27 29 accounts.google.com 142.251.36.173, 443, 49701 GOOGLEUS United States 16->29 33 4 other IPs or domains 16->33 31 192.168.2.1 unknown unknown 19->31 process8 process9 23 conhost.exe 21->23         started       
Threat name:
Document-PDF.Dropper.Heuristic
Status:
Malicious
First seen:
2023-04-06 10:40:08 UTC
File Type:
Document
Extracted files:
3
AV detection:
5 of 37 (13.51%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments