QakBot Malware Analizi

Dosya Ozellikleri

SHA256: 24a77f8bca1eb72556e1d9f1eeb2568a2d5c27a0a686d3c8e0635aefc7723144

MD5: 891266292ad96bcb125c50852a63b5d6

Dosya Tipi: one

Boyut: 140,784 byte

Ilk Gorulme: 2023-02-14

AV Imzasi: Quakbot

Raporlayan: pr0xylife

Etiketler: 1676371257, one, Qakbot, Quakbot, tok01

Statik analiz: metadata tabanli (ornek indirilmedi)

QakBot — 악성코드 프로필

QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.

악성코드 유형
Other
프로그래밍 언어
C++
C2 프로토콜
HTTPS
대상 시스템
Windows
다른 이름 (AKA)
QBot

기술 세부 정보

QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.

귀속 / 위협 행위자

Gold Lagoon, TA570 (Shatak)

기능 및 동작

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC 목록 (1 개 지표)

IOC — QakBot
# FILEPATH 24a77f8bca1eb72556e1d9f1eeb2568a2d5c27a0a686d3c8e0635aefc7723144
유형메모
filepath 24a77f8bca1eb72556e1d9f1eeb2568a2d5c27a0a686d3c8e0635aefc7723144 PDB

C2 서버 (이 패밀리에 대해 8개의 서버 기록)

주소 유형 포트 프로토콜 상태 국가
95.217.35.154 ip 443 HTTPS inactive FI
upd5.pro domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
metasta.me domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
amacey.com domain 443 HTTPS inactive —
181.174.165.208 ip 443 HTTPS sinkholed AR
212.117.180.232 ip 443 HTTPS sinkholed CH

C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.

태그
1676371257oneQakbotQuakbottok01