QakBot Malware Analizi

Dosya Ozellikleri

SHA256: b00a4d37528d938946d92a1d5e22a2fe46ce5a0ee6997f4828ff31ca7647666c

MD5: 925fa5e952e103d57a87f41d80573f68

Dosya Tipi: dll

Boyut: 495,912 byte

Ilk Gorulme: 2023-04-25

AV Imzasi: Quakbot

Imphash: 0793fc5146cb2625c14847ed7595a3e4

Raporlayan: malwarelabnet

Etiketler: dll, obama256, Qakbot, Quakbot

Statik analiz: metadata tabanli (ornek indirilmedi)

QakBot — 악성코드 프로필

QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.

악성코드 유형
Other
프로그래밍 언어
C++
C2 프로토콜
HTTPS
대상 시스템
Windows
다른 이름 (AKA)
QBot

기술 세부 정보

QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.

귀속 / 위협 행위자

Gold Lagoon, TA570 (Shatak)

기능 및 동작

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC 목록 (1 개 지표)

IOC — QakBot
# FILEPATH b00a4d37528d938946d92a1d5e22a2fe46ce5a0ee6997f4828ff31ca7647666c
유형메모
filepath b00a4d37528d938946d92a1d5e22a2fe46ce5a0ee6997f4828ff31ca7647666c PDB

C2 서버 (이 패밀리에 대해 8개의 서버 기록)

주소 유형 포트 프로토콜 상태 국가
95.217.35.154 ip 443 HTTPS inactive FI
upd5.pro domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
metasta.me domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
amacey.com domain 443 HTTPS inactive —
181.174.165.208 ip 443 HTTPS sinkholed AR
212.117.180.232 ip 443 HTTPS sinkholed CH

C2 주소는 KEYDAL 팀이 수동으로 검증한 악성코드 샘플에서만 제공됩니다. 상업적 사용은 금지됩니다.

태그
dllobama256QakbotQuakbot