MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e812f8ffb4c0db5937799b3a8ff9d798a2bcb465e99b1c903d9097a6d948e837. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



QuakBot


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e812f8ffb4c0db5937799b3a8ff9d798a2bcb465e99b1c903d9097a6d948e837
SHA3-384 hash: fd0b68b09d9b253a40da17f3bf1438b92851f30ad1a9b1594e05abab5b566348d38d9ba5c7e3b7c591239ec620038d16
SHA1 hash: 93b6f8d294a5dcce1b438e4f29b74f6ba0b2ccc1
MD5 hash: f3059d8a6a1e45a557f97a2c9993afdb
humanhash: asparagus-summer-delaware-spring
File name:e812f8ffb4c0db5937799b3a8ff9d798a2bcb465e99b1c903d9097a6d948e837
Download: download sample
Signature QuakBot
File size:601'600 bytes
First seen:2020-11-13 15:15:21 UTC
Last seen:2024-07-24 22:31:34 UTC
File type:Executable exe
MIME type:application/x-dosexec
imphash a638410bbd93bd148f53ad16f39f2b92 (2 x QuakBot)
ssdeep 12288:25S3gaOEPHybSAPLkfyx9H1V2NkVxPqjyXPp7Fp:LSEPgJ/yE7
Threatray 2 similar samples on MalwareBazaar
TLSH CFD4120CE78FC9E4CA764D32567AB3EB54331E5A88798F798F581FB6E41996C03C5280
Reporter seifreed
Tags:Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a process with a hidden window
Creating a file in the Windows subdirectories
Creating a file in the %AppData% subdirectories
Creating a process from a recently created file
Launching a process
Creating a window
Unauthorized injection to a system process
Enabling autorun by creating a file
Threat name:
Win32.Infostealer.QBot
Status:
Malicious
First seen:
2020-11-13 15:16:22 UTC
AV detection:
22 of 29 (75.86%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
n/a
Behaviour
Runs ping.exe
Suspicious behavior: EnumeratesProcesses
Suspicious use of WriteProcessMemory
Checks SCSI registry key(s)
Unpacked files
SH256 hash:
e812f8ffb4c0db5937799b3a8ff9d798a2bcb465e99b1c903d9097a6d948e837
MD5 hash:
f3059d8a6a1e45a557f97a2c9993afdb
SHA1 hash:
93b6f8d294a5dcce1b438e4f29b74f6ba0b2ccc1
SH256 hash:
734e0e02e5475087a0f31ce920b1186edf0e32090a5cd9ac86037dc3efc37744
MD5 hash:
d9d942fa9ec8290d02448b190b13e0dd
SHA1 hash:
76eb4ce9697260eb15120865f41d58ded720c21b
Detections:
win_qakbot_g0 win_qakbot_auto
SH256 hash:
6850e4b85fc37738d1f0d17d7a409eb1295a4471e1e738dcedb777a235cf2dbc
MD5 hash:
68264d5f124cc292fbfb1c898f61c273
SHA1 hash:
2804626c4e989c44926726c2547083089b38e179
Detections:
win_qakbot_g0 win_qakbot_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

  
Delivery method
Other

Comments