MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0b18d94c4abd7f0f3a3d07fd2172956f6ec9654b8cbf087954017dd92bd9e4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA 7 File information Comments

SHA256 hash: d0b18d94c4abd7f0f3a3d07fd2172956f6ec9654b8cbf087954017dd92bd9e4f
SHA3-384 hash: 697dccade4985afd5a1e4b7feabe31668f65d44933937b8b46a01cc9b9ec2e0f8f8904a01a453ebaef8dbe54348bd61e
SHA1 hash: 055e0229236497b91216b89395351ae8c9eed8f0
MD5 hash: dea287ef5916eced7808ca3704ae67a6
humanhash: december-finch-tennis-triple
File name:6526_Predstavlenie_na_naznachenie.zip
Download: download sample
Signature Quakbot
File size:12'861'229 bytes
First seen:2026-03-02 19:33:57 UTC
Last seen:2026-03-11 05:31:34 UTC
File type: zip
MIME type:application/zip
ssdeep 393216:pEx9SPTatbIaGXKI3AD0VGdGlHtrpNqK9:Y9wkInwbOHZ9
TLSH T151D633AC7AF21C879EA4516F78441FF8737840743A5CC0217262C7D9F6A31AACB95CA7
Magika zip
Reporter smica83
Tags:zip

Intelligence


File Origin
# of uploads :
2
# of downloads :
133
Origin country :
HU HU
File Archive Information

This file archive contains 2 file(s), sorted by their relevance:

File name:paymentAction
File size:12'897'655 bytes
SHA256 hash: 8e269b11ea0ccf9ba874d5175633faad52ff45cf3bc87808e864d9c4d6bd1fdd
MD5 hash: fe2cd24dc802684bfe6c60fb238d8c4b
MIME type:application/zip
Signature Quakbot
File name:6526_Predstavlenie_na_naznachenie.‌‍​pdf‌‍.lnk
File size:2'249 bytes
SHA256 hash: ddaef2e9377ce89222c3eadfb5b3c90e9a99f3d2d0635bbf5e7d8681eae051c7
MD5 hash: a9cfe3f8ad5def658e774eb2f6f0792c
MIME type:application/octet-stream
Signature Quakbot
Vendor Threat Intelligence
Verdict:
Malicious
Score:
90.9%
Tags:
vmdetect
Verdict:
Malware
YARA:
4 match(es)
Tags:
Batch Command DeObfuscated Executable Execution: CMD in LNK Execution: PowerShell in LNK LNK LOLBin LOLBin:powershell.exe Malicious PDB Path PE (Portable Executable) PE File Layout PowerShell PowerShell Call T1059.001 T1059.003 T1202: Indirect Command Execution T1204.002 Zip Archive
Threat name:
Shortcut.Trojan.Etset
Status:
Malicious
First seen:
2026-03-02 19:34:29 UTC
File Type:
Binary (Archive)
Extracted files:
37
AV detection:
11 of 38 (28.95%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Archive_in_LNK
Author:@bartblaze
Description:Identifies archive (compressed) files in shortcut (LNK) files.
Rule name:BLOWFISH_Constants
Author:phoul (@phoul)
Description:Look for Blowfish constants
Rule name:Detect_Remcos_RAT
Author:daniyyell
Description:Detects Remcos RAT payloads and commands
Rule name:LNK_sospechosos
Author:Germán Fernández
Description:Detecta archivos .lnk sospechosos
Rule name:Long_RelativePath_LNK
Author:@bartblaze
Description:Identifies shortcut (LNK) file with a long relative path. Might be used in an attempt to hide the path.
Rule name:SUSP_LNK_PowerShell
Author:SECUINFRA Falcon Team
Description:Detects the reference to powershell inside an lnk file, which is suspicious
Rule name:upxHook
Author:@r3dbU7z
Description:Detect artifacts from 'upxHook' - modification of UPX packer
Reference:https://bazaar.abuse.ch/sample/6352be8aa5d8063673aa428c3807228c40505004320232a23d99ebd9ef48478a/

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments