MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f6a8d7b8a80827bd4729cda40e959823c4c30e648a58832623fda8dae20a08ab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f6a8d7b8a80827bd4729cda40e959823c4c30e648a58832623fda8dae20a08ab
SHA3-384 hash: 3c4c70d1c5428d90b76f0b3a97035b879e9c6f6da478f4b22c29ef5edd8c86a7dfd386db57e63739c6082816f3236aee
SHA1 hash: f259653033cb741fa326442c22f58e23f36a047b
MD5 hash: b81d2ebeb8b0f6ed3e84e78ffe784777
humanhash: asparagus-coffee-bravo-uniform
File name:Cancellation_799204_Dec23.pdf
Download: download sample
Signature Quakbot
File size:186'622 bytes
First seen:2022-12-23 15:22:51 UTC
Last seen:Never
File type: pdf
MIME type:application/pdf
ssdeep 3072:+Qcfk8aPgtSyiVLFkckuQMPhB20K8HR9hYDdfddlRCFwfkFPWN50kNSFHFUmV8NC:58nwhFkZuvPDiYqdfddlVjbr03UmVru4
TLSH T18F04E0CCB13B76BFE8BB7BB3A562835D374F6525732E6587088992A4C301F42D4510AE
Reporter pr0xylife
Tags:obama233 pdf Qakbot qbot Quakbot

Intelligence


File Origin
# of uploads :
1
# of downloads :
356
Origin country :
US US
Vendor Threat Intelligence
Label:
Malicious
Suspicious Score:
9.0/10
Score Malicious:
9%
Score Benign:
1%
Result
Verdict:
UNKNOWN
Details
Document With Few Pages
Document contains between one and three pages of content. Most malicious documents are sparse in page count.
Result
Threat name:
Unknown
Detection:
malicious
Classification:
n/a
Score:
52 / 100
Signature
Clickable URLs found in PDF pointing to potentially malicious files
Found potential malicious PDF (bad image similarity)
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 772807 Sample: Cancellation_799204_Dec23.pdf Startdate: 23/12/2022 Architecture: WINDOWS Score: 52 32 agencija-sensa.com 2->32 38 Found potential malicious PDF (bad image similarity) 2->38 40 Clickable URLs found in PDF pointing to potentially malicious files 2->40 10 AcroRd32.exe 15 45 2->10         started        signatures3 process4 process5 12 chrome.exe 18 8 10->12         started        15 RdrCEF.exe 60 10->15         started        dnsIp6 34 239.255.255.250 unknown Reserved 12->34 17 chrome.exe 12->17         started        20 unarchiver.exe 4 12->20         started        36 192.168.2.1 unknown unknown 15->36 process7 dnsIp8 26 agencija-sensa.com 148.251.67.197, 49703, 49705, 80 HETZNER-ASDE Germany 17->26 28 www.google.com 142.250.203.100, 443, 49707, 49724 GOOGLEUS United States 17->28 30 4 other IPs or domains 17->30 22 7za.exe 2 20->22         started        process9 process10 24 conhost.exe 22->24         started       
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments