MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db6eb4644ac8aa6ffd71209a6c19eb460225074741a83e7e4e04c56553621583. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 2


Intelligence 2 IOCs YARA 1 File information Comments

SHA256 hash: db6eb4644ac8aa6ffd71209a6c19eb460225074741a83e7e4e04c56553621583
SHA3-384 hash: 77b74e7cc016f60ba2776297be5ad6c07321d4e9b89660d8bfacec3aef34ac977db97a467ebb4ae97f1aac62535c7a0a
SHA1 hash: 228f3dcfac080acc407ae8d077da2266c0a0fe1a
MD5 hash: 36364ec73486b69217b8c9c13b69d486
humanhash: carpet-video-solar-fourteen
File name:Trabacoli.iso.zip
Download: download sample
Signature Quakbot
File size:636'694 bytes
First seen:2022-12-12 22:20:48 UTC
Last seen:Never
File type: zip
MIME type:application/zip
Note:This file is a password protected archive. The password is: 675
ssdeep 12288:wjDDNZQhmQ2xL3He5zL4JjQ1P3BHxvO7ok8SGiKvoO5ovfX5LT/:mDv/7xLKL4OHxmUkZyvoOy/J
TLSH T1EFD4236D5DDF15BB68F92CB25426DA346922C723CD98708C12FFE6330D2A0D42C6AE1D
TrID 80.0% (.ZIP) ZIP compressed archive (4000/1)
20.0% (.PG/BIN) PrintFox/Pagefox bitmap (640x800) (1000/1)
Reporter pr0xylife
Tags:1670829462 BB10 pw-675 Qakbot Quakbot zip

Intelligence


File Origin
# of uploads :
1
# of downloads :
158
Origin country :
RU RU
File Archive Information

This file archive contains 10 file(s), sorted by their relevance:

File name:Uraniscus.jpg
File size:3'268 bytes
SHA256 hash: c6091970ab67bd727bd9bec54233ba1eb6c2272a175177329ac0152c24782a29
MD5 hash: 0ceb7293c44711848ca3bfa765985375
MIME type:image/jpeg
Signature Quakbot
File name:Lilial.txt
File size:334'962 bytes
SHA256 hash: 31c2dda5967db27475c81254e427d5e38ce6a2571264339444b322d27bcb0c61
MD5 hash: 32e06079e861fdc6849b6fd38b68afd3
MIME type:text/plain
Signature Quakbot
File name:surgery.jpeg
File size:2'211 bytes
SHA256 hash: cf50ffe9fd724c002d9e22f177bae5b6f6a76037df1a4a835284019f667082d8
MD5 hash: 930a9b2cd6ab67345d779b4bf5a8ce7d
MIME type:image/jpeg
Signature Quakbot
File name:coursing.dat
File size:334'962 bytes
SHA256 hash: c9ca22d2f9032db7109ebb4315ce3c35806cb1cc1898ec210776486a372d9dc7
MD5 hash: fc7f311cb524ecc58d55b83488f75a98
MIME type:text/plain
Signature Quakbot
File name:Preconstituent.jpg
File size:49'428 bytes
SHA256 hash: 4b7e986aeb488b4fd37b2258ad3769580c53745f34bd8cd727c69aeaab96cf5e
MD5 hash: 4d45621d610432bf5eafffe800d1b99b
MIME type:image/jpeg
Signature Quakbot
File name:Embrail.jpg
File size:29'074 bytes
SHA256 hash: a3d8694b9085449497d50c87a5cbd1acd41dd4381d423a7fad8b2410bf1bfc81
MD5 hash: 26b06fa6bd7233930d141c458a1c7da2
MIME type:image/jpeg
Signature Quakbot
File name:trophosperm.jpg
File size:7'617 bytes
SHA256 hash: 288ed837f761c5d366098d2cdb5023747b37c194914e789d8e50f88393f6ec5a
MD5 hash: c6931211b74da363b236885e9b443446
MIME type:image/jpeg
Signature Quakbot
File name:congeeing.txt
File size:2 bytes
SHA256 hash: f188fa700eb15b4b06af04d358875d6b320ecec587a6fdc2b8d5dfdf7efe7950
MD5 hash: 072bfacf555fde9accd162a180ff0ac4
MIME type:text/plain
Signature Quakbot
File name:preaccumulated.txt
File size:334'962 bytes
SHA256 hash: 31993814a0d317da86c4a7046808031c04d31bfafd59682df2d58a28977ad0be
MD5 hash: 9446ac99830c347ca53e36a5ca24f527
MIME type:text/plain
Signature Quakbot
File name:ureterogram.js
File size:64'564 bytes
SHA256 hash: 94c8b3702fd3964beb04640bf44803b8fa96b9ee5b4655d26b7641714e169406
MD5 hash: 05f30e6eb50a0253a559910a0327acca
MIME type:text/plain
Signature Quakbot
Vendor Threat Intelligence
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:AlternativesExample1

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments