🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e655332a64e4e4ac32465748c0a911abc75f7bca6d655b57cdacca6d0548093e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e655332a64e4e4ac32465748c0a911abc75f7bca6d655b57cdacca6d0548093e
SHA3-384 hash: ee652dca32296f8e903138d297c548574a8d030270aeb8229fd9176f158b4611d37370fbb0d3684629f3cf82212a9f76
SHA1 hash: 81e138c0abbbedbb9b50e8181df8f99203f922b4
MD5 hash: 5e8092fb2a42c2c5d01f0de21c22597f
humanhash: illinois-red-crazy-romeo
File name:sit.pdf
Download: download sample
Signature Quakbot
File size:52'805 bytes
First seen:2023-04-26 04:44:03 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 1536:5M9HOLi5vNxDhLoR10PN56U8rv5Nua/2kE2g9:Y+CvNxDmRSN56maa9
TLSH T14F33F1FAD5A8CDC4B9C7D465827E332AC158F508B8CE24C501179DA79E80CBFBA983D5
Reporter Jazzo74911657
Tags:pdf Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
502
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
remote
Label:
Malicious
Suspicious Score:
9.6/10
Score Malicious:
96%
Score Benign:
4%
Result
Threat name:
n/a
Detection:
malicious
Classification:
expl.evad
Score:
72 / 100
Signature
Antivirus detection for URL or domain
Creates processes via WMI
Downloads suspicious files via Chrome
Machine Learning detection for sample
Suspicious execution chain found
System process connects to network (likely due to code injection or exploit)
Behaviour
Behavior Graph:
behaviorgraph top1 signatures2 2 Behavior Graph ID: 854149 Sample: sit.pdf Startdate: 26/04/2023 Architecture: WINDOWS Score: 72 53 Antivirus detection for URL or domain 2->53 55 Machine Learning detection for sample 2->55 57 Downloads suspicious files via Chrome 2->57 59 Suspicious execution chain found 2->59 8 chrome.exe 18 8 2->8         started        12 AcroRd32.exe 15 39 2->12         started        14 rundll32.exe 2->14         started        16 WmiPrvSE.exe 2->16         started        process3 dnsIp4 47 192.168.2.4 unknown unknown 8->47 49 239.255.255.250 unknown Reserved 8->49 37 C:\Users\user\Downloads\Kzsn.zip (copy), Zip 8->37 dropped 18 unarchiver.exe 4 8->18         started        20 chrome.exe 8->20         started        23 RdrCEF.exe 69 12->23         started        file5 process6 dnsIp7 25 cmd.exe 2 2 18->25         started        27 7za.exe 2 18->27         started        39 johkass.com 198.54.115.64, 49687, 49688, 80 NAMECHEAP-NETUS United States 20->39 41 www.google.com 142.250.203.100, 443, 49690, 49729 GOOGLEUS United States 20->41 45 4 other IPs or domains 20->45 43 192.168.2.1 unknown unknown 23->43 process8 process9 29 wscript.exe 17 25->29         started        33 conhost.exe 25->33         started        35 conhost.exe 27->35         started        dnsIp10 51 bristolroofingca.com 192.185.98.171, 49695, 80 UNIFIEDLAYER-AS-1US United States 29->51 61 System process connects to network (likely due to code injection or exploit) 29->61 63 Creates processes via WMI 29->63 signatures11
Threat name:
Document-PDF.Trojan.Heuristic
Status:
Malicious
First seen:
2023-04-25 18:57:07 UTC
File Type:
Document
Extracted files:
3
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments