MALICIOUS — 8a9ee5a23cb20e037d47ca9af0ca8716b871b8879fe66bddeaeb415657fb6b48
MALICIOUS — 8a9ee5a23cb20e037d47ca9af0ca8716b871b8879fe66bddeaeb415657fb6b48 is a pe sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (93/100), attributed to the Qakbot family. 7 of 52 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
8a9ee5a23cb20e037d47ca9af0ca8716b871b8879fe66bddeaeb415657fb6b48 - SHA-1:
d85e3d1b23824e583781102f6ed50235f81dcd75 - MD5:
40ccebfee2b91c0dd3f39de70a39f650 - imphash:
9e62f3cd2189054f4bb90527a7ba86cc - ssdeep:
12288:OQyVN+P9loEP1BhI/XvnnRwe40F445OfUZjsAzZat6mIo:ZOEPkSTs5nT6817zZaP - TLSH:
T1E24DAE7E23277613DA37CE240991BF4D0071F86A10B66C8953AB643EFAE9C5B1A44358 - Submitted as: 8a9ee5a23cb20e037d47ca9af0ca8716b871b8879fe66bddeaeb415657fb6b48
- File type: pe · Size: 601088 bytes
- Verdict: malicious (93/100) · Family: Qakbot
Detections (7 of 52 engines)
- capa (capabilities): capability:collection/keylog
- ClamAV (daily): Win.Trojan.Qakbot-9908979-1
- YARA: JPCERT/CC: JPCERT_HUILoader_PlugX_SideLoad
- Microsoft Defender: Trojan:Win32/Bunitucrypt.DE!MTB
- Emsisoft (Emergency Kit): Gen:Variant.Qbot.642
- Trellix Stinger (McAfee): Trojan-FTKL!40CCEBFEE2B9
- Kaspersky (KVRT): UDS:Trojan.Win32.Injuke.gen
MITRE ATT&CK
Why this verdict
The malicious score of 93/100 is the fusion of 3 weighted signals:
- ClamAV (daily) flagged Win.Trojan.Qakbot-9908979-1 (rule
Win.Trojan.Qakbot-9908979-1) - engine signal, weight 0.90, confidence 0.95 - capture keystrokes (rule
capture keystrokes) - capa signal, weight 0.40, confidence 0.80 - YARA: JPCERT/CC flagged JPCERT_HUILoader_PlugX_SideLoad (rule
JPCERT_HUILoader_PlugX_SideLoad) - engine signal, weight 0.35, confidence 0.70
Dynamic analysis
No runtime behaviour was captured for this sample, so the analysis above is static only. That is a limit of this run rather than evidence the sample does nothing.
File paths
- T:\:d:l:t:
- O:\:k:
- X:\:`:d:h:l:p:t:x:
- I:\:`:o:{:
- W:\:a:l:q:v:
- X:\:`:d:r:
- X:\:`:d:h:l:p:x:
More Qakbot samples · Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report