MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c5df8f8328103380943d8ead5345ca9fe8a9d495634db53cf9ea3266e353a3b1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: c5df8f8328103380943d8ead5345ca9fe8a9d495634db53cf9ea3266e353a3b1
SHA3-384 hash: 10374d654b9f56f3a11c6c2c0f0dafc61531e5f548dbd11fab5605551432270889f42e42151ee4324773a70d2b498875
SHA1 hash: 65e523c6adf2957bd898d4c429e70985268e2804
MD5 hash: 7805b0885e64e4ab56bbee1e7a42db0b
humanhash: nitrogen-sixteen-oregon-uncle
File name:WW.js
Download: download sample
Signature Quakbot
File size:9'767 bytes
First seen:2022-11-17 15:19:36 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:juSLjDJq0Tavgx685UIroAKbP2KTMhS0OGYm5llWVjAvNzAWMuEvk7MgG+r5A6:FVq2k785UIro8KTMhSeYm5P2jiuuEjP4
TLSH T183125B5F3D53ECF911F37A91EDDA24F5DC1A292288622046189FFB30421C7DA6D151DB
Reporter pr0xylife
Tags:1668683197 BB06 js Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
276
Origin country :
IE IE
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Base64 Encoded URL
Detected an ANSI or UNICODE http:// or https:// base64 encoded URL prefix.
Threat name:
Script-JS.Trojan.Magniber
Status:
Malicious
First seen:
2022-11-17 15:20:13 UTC
File Type:
Text (JavaScript)
AV detection:
1 of 39 (2.56%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments