🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dfa9a6d275eea4fce73e3d34eb48b472c5804f4de7b0985a2f1b88d4eee52db6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: dfa9a6d275eea4fce73e3d34eb48b472c5804f4de7b0985a2f1b88d4eee52db6
SHA3-384 hash: 2987868a0357ceb33b7aa8dd7cc38edd64e00807b71a5d3b772cd6a35086e8f71fb2e70063518feb5443be5da5de93af
SHA1 hash: 80532b3c4fbaf3dd993101147cf9c1afe2afbb58
MD5 hash: 784835ba3cbd86d83b9778e885061084
humanhash: september-quebec-spring-wisconsin
File name:N.pdf
Download: download sample
Signature Quakbot
File size:144'852 bytes
First seen:2023-06-02 11:08:44 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:blFbF1uJb7aY8P3QYYYYYYYYYYYYYYYYYYYYYYYYYYYYYEqPcOLbzsg3BI:bnx1uJb7aYs3QYYYYYYYYYYYYYYYYYY9
TLSH T1C7E38D9CE94DD88CE5F5A7F2A361F0E9D21EB3238FC918B2659D0F976103C1AD947482
Reporter proxylife
Tags:1685686808 BB30 pdf Qakbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
515
Origin country :
US US
Vendor Threat Intelligence
Label:
Benign
Suspicious Score:
10/10
Score Malicious:
1%
Score Benign:
99%
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
76 / 100
Signature
Creates processes via WMI
Downloads suspicious files via Chrome
Multi AV Scanner detection for domain / URL
Sigma detected: Execute DLL with spoofed extension
Suspicious execution chain found
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 880550 Sample: N.pdf Startdate: 02/06/2023 Architecture: WINDOWS Score: 76 57 Multi AV Scanner detection for domain / URL 2->57 59 Sigma detected: Execute DLL with spoofed extension 2->59 61 Downloads suspicious files via Chrome 2->61 63 Suspicious execution chain found 2->63 8 chrome.exe 8 2->8         started        12 conhost.exe 2->12         started        14 AcroRd32.exe 15 37 2->14         started        16 WmiPrvSE.exe 2->16         started        process3 dnsIp4 55 239.255.255.250 unknown Reserved 8->55 43 C:\Users\...\document_C369_Jun_2.zip (copy), Zip 8->43 dropped 18 unarchiver.exe 4 8->18         started        20 chrome.exe 8->20         started        23 conhost.exe 12->23         started        25 RdrCEF.exe 64 14->25         started        file5 process6 dnsIp7 27 cmd.exe 2 2 18->27         started        29 7za.exe 2 18->29         started        47 www.google.com 142.250.203.100, 443, 49719, 49730 GOOGLEUS United States 20->47 49 accounts.google.com 142.250.203.109, 443, 49716 GOOGLEUS United States 20->49 53 3 other IPs or domains 20->53 31 conhost.exe 23->31         started        51 192.168.2.1 unknown unknown 25->51 process8 process9 33 wscript.exe 15 27->33         started        37 conhost.exe 27->37         started        39 conhost.exe 29->39         started        41 rundll32.exe 31->41         started        dnsIp10 45 151.236.28.95, 49721, 80 NFORCENL European Union 33->45 65 System process connects to network (likely due to code injection or exploit) 33->65 67 Creates processes via WMI 33->67 signatures11
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments