MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d34a8790bafa9607cdd0c2edcf4d9ca35d23335d5dab867f4b1135c074606861. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments 1

SHA256 hash: d34a8790bafa9607cdd0c2edcf4d9ca35d23335d5dab867f4b1135c074606861
SHA3-384 hash: 2ff6f089973b9ee4cd75e84f5723ad253b2342e930dec2b0521a4321ee4feb9d2dcdd724c827b85ddf8856c837041b97
SHA1 hash: d80d4623c33825d98395529a28883139296f9b77
MD5 hash: 838abbe46d14ed4e23335ad4aa51a6d2
humanhash: hotel-mobile-carbon-potato
File name:838abbe46d14ed4e23335ad4aa51a6d2.dll
Download: download sample
Signature Quakbot
File size:591'204 bytes
First seen:2021-04-13 07:59:28 UTC
Last seen:2021-04-13 08:55:08 UTC
File type:DLL dll
MIME type:application/x-dosexec
ssdeep 12288:LAlF6Uoww/SY6TB0bbg3dW3JHrvVDPjjqXtBIV0Q5a:LAboz/I6budWhdq97
TLSH 0AC46B36F1D3C437C5337A7CCD5F5199A82ABE612D28A8577BE40C089F3A681392D2D6
Reporter abuse_ch
Tags:dll Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
185
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Sending a UDP request
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Suspicious use of WriteProcessMemory
Unpacked files
SH256 hash:
d34a8790bafa9607cdd0c2edcf4d9ca35d23335d5dab867f4b1135c074606861
MD5 hash:
838abbe46d14ed4e23335ad4aa51a6d2
SHA1 hash:
d80d4623c33825d98395529a28883139296f9b77
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Quakbot

DLL dll d34a8790bafa9607cdd0c2edcf4d9ca35d23335d5dab867f4b1135c074606861

(this sample)

  
Delivery method
Distributed via web download

Comments



Avatar
a̵c̵c̸i̵d̷e̵n̷t̴a̷l̴r̵e̷b̸e̴l̸ commented on 2021-04-14 08:53:54 UTC

================================================================================
MBC behaviors list (github.com/accidentalrebel/mbcscan):
================================================================================
0) [C0026.002] Data Micro-objective::XOR::Encode Data