QakBot Malware Analizi

Dosya Ozellikleri

SHA256: 5e30ec1e1b1e5e64a98dfe05ca8d151ed1c0180e8ba3a01f1da8b26d890f8300

MD5: 92bd25eaf2122b46434941a2488cb5c9

Dosya Tipi: dll

Boyut: 1,165,712 byte

Ilk Gorulme: 2023-03-24

AV Imzasi: Quakbot

Imphash: c838d1a15fac6fddafb036f322459302

Raporlayan: pr0xylife

Etiketler: 1679552371, BB20, dll, Qakbot, Quakbot

Statik analiz: metadata tabanli (ornek indirilmedi)

QakBot — 恶意软件档案

QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.

恶意软件类型
Other
编程语言
C++
C2协议
HTTPS
目标系统
Windows
别名 (AKA)
QBot

技术细节

QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.

归因 / 威胁行为者

Gold Lagoon, TA570 (Shatak)

能力与行为

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC列表 (1 个指标)

IOC — QakBot
# FILEPATH 5e30ec1e1b1e5e64a98dfe05ca8d151ed1c0180e8ba3a01f1da8b26d890f8300
类型备注
filepath 5e30ec1e1b1e5e64a98dfe05ca8d151ed1c0180e8ba3a01f1da8b26d890f8300 PDB

C2服务器 (该家族共有 8 台已记录服务器)

地址 类型 端口 协议 状态 国家
95.217.35.154 ip 443 HTTPS inactive FI
upd5.pro domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
metasta.me domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
amacey.com domain 443 HTTPS inactive —
181.174.165.208 ip 443 HTTPS sinkholed AR
212.117.180.232 ip 443 HTTPS sinkholed CH

C2 地址仅来自 KEYDAL 团队人工验证的恶意软件样本。禁止用于商业用途。

标签
1679552371BB20dllQakbotQuakbot