MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0f396309db14bbe988e8ae6ba6dfb4451fc9db830484dcb7dec830b74d8467a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d0f396309db14bbe988e8ae6ba6dfb4451fc9db830484dcb7dec830b74d8467a
SHA3-384 hash: c63c3e96de8ebe6fc2853d158612ac9a4a658c04aa425f466ef9a4f1fe9b9230a9183afd462033edd69c05559c804147
SHA1 hash: 4784a7c288fbffaea4e5c10cfc2da208578977a2
MD5 hash: b6377f4364852191e440269dc0225850
humanhash: helium-batman-lamp-michigan
File name:AS.js
Download: download sample
Signature Quakbot
File size:9'491 bytes
First seen:2022-11-28 13:09:27 UTC
Last seen:Never
File type:Java Script (JS) js
MIME type:text/plain
ssdeep 192:CSLj5Uravgx685UIhpHKbP2KTMhS0OGYm9lWVjAvNzAWM5Evk7MgG+r5A0:N5Kk785UIhp/KTMhSeYmn2jiu5EjP+rV
TLSH T1CE125B5B3C53ECFA11B77981EEDA20F9DC1A296248A210052C5FFB30421C7EA6D112D7
Reporter pr0xylife
Tags:1669628564 BB08 js Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
330
Origin country :
RU RU
Vendor Threat Intelligence
Result
Verdict:
UNKNOWN
Details
Base64 Encoded URL
Detected an ANSI or UNICODE http:// or https:// base64 encoded URL prefix.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
evad
Score:
60 / 100
Signature
Bypasses PowerShell execution policy
JavaScript source code contains functionality to generate code involving a shell, file or stream
JScript performs obfuscated calls to suspicious functions
Wscript starts Powershell (via cmd or directly)
Behaviour
Behavior Graph:
Result
Malware family:
n/a
Score:
  7/10
Tags:
n/a
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious use of AdjustPrivilegeToken
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
Checks computer location settings
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments