🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d554cf5e1dd65dc5d013e04bce060bbe8029302c0da6d02fad3f58010c5a554b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 11


Intelligence 11 IOCs YARA File information Comments

SHA256 hash: d554cf5e1dd65dc5d013e04bce060bbe8029302c0da6d02fad3f58010c5a554b
SHA3-384 hash: 8cc0e3456d4032e50811dbcec6b5857ef60fbb23cebc21caa1aae27be0f08204aed0390fe9bfb0dd25af9f000d3fdaca
SHA1 hash: 8b076bb8305a215b2b31d2c280e818dc93bd2768
MD5 hash: 044033044c3dcbe70b37dfa51656c99d
humanhash: fifteen-beryllium-triple-march
File name:d554cf5e1dd65dc5d013e04bce060bbe8029302c0da6d02fad3f58010c5a554b
Download: download sample
Signature Quakbot
File size:686'576 bytes
First seen:2022-07-09 07:11:49 UTC
Last seen:2022-07-09 07:43:22 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash b3eb5f2cb0e5c330158023ae1978afd1 (12 x Quakbot)
ssdeep 12288:bHl4sryeYLd4LtvckUzl/FcdjhvDr7UTGoChBQTr:bmYYLd4dsernUGodr
Threatray 14 similar samples on MalwareBazaar
TLSH T19BE49F26F7D08833D27316389C5B63A4A8357E50293868962FFC2E4C4F39B817A75797
TrID 47.6% (.EXE) Win32 Executable Delphi generic (14182/79/4)
15.1% (.EXE) Win32 Executable (generic) (4505/5/1)
10.0% (.MZP) WinArchiver Mountable compressed Archive (3000/1)
6.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
6.8% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 399998ecd4d46c0e (573 x Quakbot, 312 x GCleaner, 137 x ArkeiStealer)
Reporter JAMESWT_WT
Tags:dll Quakbot signed TOPFLIGHT GROUP LIMITED

Code Signing Certificate

Organisation:TOPFLIGHT GROUP LIMITED
Issuer:Sectigo Public Code Signing CA R36
Algorithm:sha384WithRSAEncryption
Valid from:2022-06-24T00:00:00Z
Valid to:2023-06-24T23:59:59Z
Serial number: 5b1f9ec88d185631ab032dbfd5166c0d
Intelligence: 12 malware samples on MalwareBazaar are signed with this code signing certificate
MalwareBazaar Blocklist:This certificate is on the MalwareBazaar code signing certificate blocklist (CSCB)
Thumbprint Algorithm:SHA256
Thumbprint: a46234c01e9f9904e500aefad4b5718d86aaec4e084b3d8ffbfe5724f8ddda45
Source:This information was brought to you by ReversingLabs A1000 Malware Analysis Platform

Intelligence


File Origin
# of uploads :
2
# of downloads :
312
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Clean
Maliciousness:

Behaviour
Launching a process
Searching for the window
Creating a window
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
greyware keylogger overlay packed
Result
Threat name:
CryptOne, Qbot
Detection:
malicious
Classification:
troj.evad
Score:
100 / 100
Signature
Allocates memory in foreign processes
Contains functionality to detect sleep reduction / modifications
Creates files in the system32 config directory
Encrypted powershell cmdline option found
Injects code into the Windows Explorer (explorer.exe)
Maps a DLL or memory area into another process
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Overwrites code with unconditional jumps - possibly settings hooks in foreign process
Sigma detected: Schedule system process
Uses schtasks.exe or at.exe to add and modify task schedules
Writes to foreign memory regions
Yara detected CryptOne packer
Yara detected Qbot
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 660188 Sample: WsYTZr2ZxI Startdate: 09/07/2022 Architecture: WINDOWS Score: 100 48 Multi AV Scanner detection for dropped file 2->48 50 Multi AV Scanner detection for submitted file 2->50 52 Yara detected CryptOne packer 2->52 54 3 other signatures 2->54 8 loaddll32.exe 1 2->8         started        11 powershell.exe 11 2->11         started        13 powershell.exe 2->13         started        process3 signatures4 56 Overwrites code with unconditional jumps - possibly settings hooks in foreign process 8->56 58 Injects code into the Windows Explorer (explorer.exe) 8->58 60 Writes to foreign memory regions 8->60 64 2 other signatures 8->64 15 explorer.exe 8 1 8->15         started        19 cmd.exe 1 8->19         started        62 Creates files in the system32 config directory 11->62 21 regsvr32.exe 11->21         started        23 conhost.exe 11->23         started        25 regsvr32.exe 13->25         started        27 conhost.exe 13->27         started        process5 file6 44 C:\Users\user\Desktop\WsYTZr2ZxI.dll, PE32 15->44 dropped 46 Uses schtasks.exe or at.exe to add and modify task schedules 15->46 29 schtasks.exe 1 15->29         started        31 rundll32.exe 19->31         started        34 regsvr32.exe 21->34         started        36 regsvr32.exe 25->36         started        signatures7 process8 signatures9 38 conhost.exe 29->38         started        66 Contains functionality to detect sleep reduction / modifications 31->66 40 WerFault.exe 23 9 31->40         started        42 explorer.exe 31->42         started        process10
Threat name:
Win32.Backdoor.Quakbot
Status:
Malicious
First seen:
2022-07-08 23:08:52 UTC
File Type:
PE (Dll)
Extracted files:
38
AV detection:
19 of 26 (73.08%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:obama199 campaign:1657265474 banker stealer trojan
Behaviour
Creates scheduled task(s)
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Program crash
Qakbot/Qbot
Malware Config
C2 Extraction:
121.7.223.45:2222
67.209.195.198:443
148.64.96.100:443
92.132.132.81:2222
217.128.122.65:2222
47.180.172.159:443
173.174.216.62:443
70.46.220.114:443
32.221.224.140:995
69.14.172.24:443
117.248.109.38:21
94.59.15.180:2222
38.70.253.226:2222
217.165.157.202:995
41.228.22.180:443
67.165.206.193:993
172.115.177.204:2222
186.90.153.162:2222
47.23.89.60:993
120.150.218.241:995
93.48.80.198:995
89.211.209.234:2222
197.89.12.70:443
208.107.221.224:443
24.178.196.158:2222
66.230.104.103:443
118.161.14.242:995
24.158.23.166:995
100.38.242.113:995
37.208.132.76:50010
63.143.92.99:995
182.191.92.203:995
86.97.246.166:1194
74.14.5.179:2222
40.134.246.185:995
111.125.245.116:995
173.21.10.71:2222
76.25.142.196:443
142.186.49.224:2222
118.161.14.242:443
174.69.215.101:443
187.172.164.12:443
129.208.151.177:995
70.51.137.244:2222
190.252.242.69:443
24.55.67.176:443
103.246.242.202:443
89.101.97.139:443
47.156.129.52:443
72.252.157.93:993
72.252.157.93:990
72.252.157.93:995
177.94.65.26:32101
24.139.72.117:443
82.41.63.217:443
179.158.105.44:443
81.132.186.218:2078
201.172.20.167:2222
37.186.58.99:995
37.34.253.233:443
125.25.133.223:443
45.241.254.69:993
39.49.41.221:995
196.203.37.215:80
88.240.59.52:443
39.44.60.200:995
86.97.10.37:443
86.98.157.114:993
109.12.111.14:443
81.193.30.90:443
39.52.59.221:995
39.41.16.210:995
106.51.48.188:50001
86.97.209.138:2222
104.34.212.7:32103
86.213.75.30:2078
45.46.53.140:2222
39.57.56.11:995
84.241.8.23:32103
2.178.166.220:61202
24.43.99.75:443
101.50.67.155:995
41.13.224.28:443
108.56.213.219:995
189.253.167.141:443
5.32.41.45:443
120.61.1.141:443
177.189.180.214:32101
94.36.193.176:2222
39.53.124.57:995
80.11.74.81:2222
41.84.224.109:443
103.116.178.85:995
209.15.76.228:443
184.97.29.26:443
102.65.66.66:443
39.52.221.9:995
191.112.26.57:443
210.246.4.69:995
Unpacked files
SH256 hash:
e5f65f9bace58f3396e84b64ae2fbd508bffff96710b0b4f8a8501b3fb0a97a4
MD5 hash:
2d7e73f29e4118c4147c1dd7a8dddbc3
SHA1 hash:
ed766d5fa498b77bdee0d401b41f2fec8c67162a
SH256 hash:
d554cf5e1dd65dc5d013e04bce060bbe8029302c0da6d02fad3f58010c5a554b
MD5 hash:
044033044c3dcbe70b37dfa51656c99d
SHA1 hash:
8b076bb8305a215b2b31d2c280e818dc93bd2768
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments