🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cd36d482a2c8e8cc753d57ef4b4ea7b9574ca457a443652d8d82da3d93402323. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: cd36d482a2c8e8cc753d57ef4b4ea7b9574ca457a443652d8d82da3d93402323
SHA3-384 hash: 39b2700e98e50d3ff56c8b7df407a9814753e4f8c0f85229106b2f9a92f659511810d0c634ee443ecc9da540b53c3bb6
SHA1 hash: 491eb31684d263de03eedb67f37cbf0c4e92fcc8
MD5 hash: b8e4fe394ddbd64b2ddc4023e4cba708
humanhash: twenty-venus-five-eight
File name:ComplaintApril_1337.pdf
Download: download sample
Signature Quakbot
File size:92'930 bytes
First seen:2023-04-11 16:52:08 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:S99mEYrvrlOr3aCF4lOVPipU04FIEXuvgOOgQJ8DX0bo+kcZ23gAbvgM6Ktaoqkm:wkxOrLFDVPiC0423w8DX0rkD1gHkhBm
TLSH T18993E0D8827659D8D0424AF8FB4F45B200CFA1F25A11184B3D2CCDDB5742E87F576BA2
TrID 93.4% (.PDF) Adobe Portable Document Format (password protected) (71500/1/20)
6.5% (.PDF) Adobe Portable Document Format (5000/1)
Reporter proxylife
Tags:obama250 pdf Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
449
Origin country :
RU RU
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
3.1/10
Score Malicious:
31%
Score Benign:
69%
Result
Threat name:
Unknown
Detection:
suspicious
Classification:
evad
Score:
20 / 100
Signature
PDF is encrypted and contains forms
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 844880 Sample: ComplaintApril_1337.pdf Startdate: 11/04/2023 Architecture: WINDOWS Score: 20 13 PDF is encrypted and contains forms 2->13 6 AcroRd32.exe 15 37 2->6         started        process3 process4 8 RdrCEF.exe 66 6->8         started        dnsIp5 11 192.168.2.1 unknown unknown 8->11
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments