QakBot Malware Analizi

Dosya Ozellikleri

SHA256: 48ea2cef873e462c5f6b2912268bbd2e8f267a77357626e12a17aeab4eb33b71

MD5: ba0ca01029fa22351a0b81e3a44b8b90

Dosya Tipi: dll

Boyut: 747,520 byte

Ilk Gorulme: 2022-12-15

AV Imzasi: Quakbot

Imphash: 6d24fdc20ad4f407cb9afdc29a1dde7b

Raporlayan: pr0xylife

Etiketler: 1671090444, BB10, dll, Qakbot, Quakbot

Statik analiz: metadata tabanli (ornek indirilmedi)

QakBot — 악성코드 프로필

QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.

악성코드 유형
Other
프로그래밍 언어
C++
C2 프로토콜
HTTPS
대상 시스템
Windows
다른 이름 (AKA)
QBot

기술 세부 정보

QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.

귀속 / 위협 행위자

Gold Lagoon, TA570 (Shatak)

기능 및 동작

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC 목록 (1 개 지표)

IOC — QakBot
# FILEPATH 48ea2cef873e462c5f6b2912268bbd2e8f267a77357626e12a17aeab4eb33b71
유형메모
filepath 48ea2cef873e462c5f6b2912268bbd2e8f267a77357626e12a17aeab4eb33b71 PDB

C2 서버 (이 패밀리에 대해 8개의 서버 기록)

주소 유형 포트 프로토콜 상태 국가
95.217.35.154 ip 443 HTTPS inactive FI
upd5.pro domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
metasta.me domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
amacey.com domain 443 HTTPS inactive —
181.174.165.208 ip 443 HTTPS sinkholed AR
212.117.180.232 ip 443 HTTPS sinkholed CH

C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.

태그
1671090444BB10dllQakbotQuakbot