MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe481c946b397fcbad882f8a419fd0e6e227c0564aa128c820b7096bc2fe1ae0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Quakbot


Vendor detections: 12


Intelligence 12 IOCs YARA 2 File information Comments

SHA256 hash: fe481c946b397fcbad882f8a419fd0e6e227c0564aa128c820b7096bc2fe1ae0
SHA3-384 hash: 3c7c1e734dca5088579f7f9652424e33167d7520c527991a88f7a7a0e08dc13fd8272510b85e920162841436b45c7ab2
SHA1 hash: 0f7fd4bf22ac252ce7d4407160d70c05f4ebfa5f
MD5 hash: fc7120dfbd08e8330026e63b88ddd45a
humanhash: table-item-hamper-diet
File name:ofTake.db
Download: download sample
Signature Quakbot
File size:654'848 bytes
First seen:2022-09-16 17:13:59 UTC
Last seen:2022-09-16 18:17:51 UTC
File type:DLL dll
MIME type:application/x-dosexec
imphash 92a7168d583d978b141f2c6fc4b53070 (4 x Quakbot)
ssdeep 12288:GOSe1J015+z6oZZdf/zxY5lbV6dR84Q7yLCgsy:9j1y5+z6oLdzxm0b8eTs
Threatray 1'387 similar samples on MalwareBazaar
TLSH T13ED4AF23B2E048B7D173267C9C3B72AC943A7E102F2C954B6BD41D4D5F3A6407A6A397
TrID 47.6% (.EXE) Win32 Executable Delphi generic (14182/79/4)
15.1% (.EXE) Win32 Executable (generic) (4505/5/1)
10.0% (.MZP) WinArchiver Mountable compressed Archive (3000/1)
6.9% (.EXE) Win16/32 Executable Delphi generic (2072/23)
6.8% (.EXE) OS/2 Executable (generic) (2029/13)
File icon (PE):PE icon
dhash icon 399998ecd4d46c0e (572 x Quakbot, 137 x ArkeiStealer, 82 x GCleaner)
Reporter thomaspatzke
Tags:dll obama203 Qakbot Quakbot

Intelligence


File Origin
# of uploads :
2
# of downloads :
294
Origin country :
n/a
Vendor Threat Intelligence
Result
Verdict:
Suspicious
Maliciousness:

Behaviour
Сreating synchronization primitives
Creating a window
Searching for synchronization primitives
Launching a process
Modifying an executable file
Unauthorized injection to a system process
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
greyware keylogger
Result
Verdict:
MALICIOUS
Details
Windows PE Executable
Found a Windows Portable Executable (PE) binary. Depending on context, the presence of a binary is suspicious or malicious.
Threat name:
Win32.Trojan.QBot
Status:
Malicious
First seen:
2022-09-16 17:14:09 UTC
File Type:
PE (Dll)
Extracted files:
38
AV detection:
18 of 26 (69.23%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:qakbot botnet:obama203 campaign:1663242106 banker stealer trojan
Behaviour
Suspicious behavior: EnumeratesProcesses
Suspicious behavior: MapViewOfSection
Suspicious use of WriteProcessMemory
Program crash
Qakbot/Qbot
Malware Config
C2 Extraction:
81.131.161.131:2078
217.165.85.223:993
37.210.148.30:995
200.161.62.126:32101
78.100.225.34:2222
119.82.111.158:443
66.181.164.43:443
134.35.13.45:443
193.3.19.37:443
99.232.140.205:2222
197.94.210.133:443
87.243.113.104:995
84.38.133.191:443
14.184.97.67:443
123.240.131.1:443
194.166.207.160:995
78.168.87.170:2222
180.180.131.95:443
41.96.56.224:443
190.44.40.48:995
191.84.204.214:995
191.97.234.238:995
105.99.214.62:995
70.51.132.197:2222
91.116.160.252:443
196.64.231.231:443
179.111.111.88:32101
2.182.104.151:990
72.88.245.71:443
99.253.251.74:443
154.181.203.230:995
64.207.215.69:443
85.114.110.108:443
102.38.96.108:995
109.158.159.179:993
186.105.182.127:443
71.10.27.196:2222
41.69.118.117:995
47.146.182.110:443
197.204.143.46:443
194.49.79.231:443
88.242.228.16:53
88.231.221.198:443
175.110.231.67:443
196.92.172.24:8443
186.50.245.74:995
100.1.5.250:995
78.182.113.80:443
41.96.171.218:443
154.246.182.210:443
81.214.220.237:443
187.205.222.100:443
95.136.41.50:443
190.158.58.236:443
105.99.80.23:443
105.197.192.21:995
181.127.138.30:443
167.60.82.242:995
196.112.34.71:443
88.251.38.53:443
68.224.229.42:443
37.37.206.87:995
37.76.197.124:443
188.157.6.170:443
68.50.190.55:443
181.111.20.201:443
31.166.116.171:443
84.238.253.171:443
197.49.50.44:443
169.159.95.135:2222
45.160.124.211:995
113.22.102.155:443
211.248.176.4:443
186.167.249.206:443
85.98.206.165:995
139.195.132.210:2222
182.213.208.5:443
201.177.163.176:443
45.183.234.180:443
98.180.234.228:443
184.82.110.50:995
179.24.245.193:995
94.99.110.157:995
181.56.125.32:443
119.42.124.18:443
181.231.229.133:443
2.89.78.130:993
70.81.121.237:2222
181.81.116.144:443
197.11.128.156:443
41.142.132.190:443
105.111.60.60:995
154.238.151.197:995
156.219.49.22:995
179.223.89.154:995
102.101.231.141:443
220.116.250.45:443
138.0.114.166:443
62.114.193.186:995
85.98.46.114:443
184.99.123.118:443
186.120.58.88:443
46.186.216.41:32100
156.213.107.29:995
27.73.215.46:32102
68.151.196.147:995
181.59.3.118:443
68.129.232.158:443
45.241.140.181:995
212.156.51.194:443
87.75.195.211:443
1.10.253.207:443
87.220.229.164:2222
109.200.165.82:443
41.105.197.244:443
190.59.247.136:995
219.69.103.199:443
61.105.45.244:443
105.105.104.0:443
169.1.47.111:443
210.195.18.76:2222
118.175.247.124:995
88.246.170.2:443
95.10.13.82:443
171.248.157.128:995
118.68.220.199:443
139.195.63.45:2222
118.216.99.232:443
181.80.133.202:443
102.40.236.32:995
46.116.229.16:443
61.70.29.53:443
179.108.32.195:443
171.238.230.59:443
81.56.22.251:995
31.32.180.179:443
186.64.87.202:443
85.139.203.42:32101
Unpacked files
SH256 hash:
9b18dc43125ed9080da3bc31232b6294bce32b30e838e1bc5f27e3c94445bcb5
MD5 hash:
28c6fddfe6dc10dfd65b521f474c3341
SHA1 hash:
564c764a55f064d07381fc8fdba92f72b91862f3
SH256 hash:
b4e4bb1b180b085059921316af41ae5400ac6d11020c8f58adec0b8d80d0301a
MD5 hash:
9af488f6f87b48b48479f08c554e334d
SHA1 hash:
2469019fd86a6923b3e8d470407da5daa9904f14
Detections:
Qakbot win_qakbot_auto
SH256 hash:
fe481c946b397fcbad882f8a419fd0e6e227c0564aa128c820b7096bc2fe1ae0
MD5 hash:
fc7120dfbd08e8330026e63b88ddd45a
SHA1 hash:
0f7fd4bf22ac252ce7d4407160d70c05f4ebfa5f
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:RansomwareTest4
Author:Daoyuan Wu
Description:Test Ransomware YARA rules
Rule name:RansomwareTest5
Author:Daoyuan Wu
Description:Test Ransomware YARA rules

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Malspam

Quakbot

DLL dll fe481c946b397fcbad882f8a419fd0e6e227c0564aa128c820b7096bc2fe1ae0

(this sample)

  
Delivery method
Distributed via e-mail attachment

Comments