QakBot Malware Analizi

Dosya Ozellikleri

SHA256: ff0730a8693c2dea990402e8f5ba3f9a9c61df76602bc6d076ddbc3034d473c0

MD5: aed7110a64e1a7be0cda22a92c43bab3

Dosya Tipi: dll

Boyut: 609,338 byte

Ilk Gorulme: 2023-02-28

AV Imzasi: Quakbot

Imphash: 001b26f64621bf924e8e5fcf57e6ac98

Raporlayan: pr0xylife

Etiketler: 1677490643, BB17, dll, Qakbot, Quakbot

Statik analiz: metadata tabanli (ornek indirilmedi)

QakBot — Malware Profili

QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.

Malware Tipi
Other
Programlama Dili
C++
C2 Protokolü
HTTPS
Hedef Sistemler
Windows
Diğer Adlar (AKA)
QBot

Teknik Detaylar

QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.

Atıf / Tehdit Aktörü

Gold Lagoon, TA570 (Shatak)

Yetenekler ve Davranış

Zararlı Yazılım Aktivitesi
Kalıcılık Mekanizması
C2 İletişimi
Anti-Analiz

IOC Listesi (1 gösterge)

IOC — QakBot
# FILEPATH ff0730a8693c2dea990402e8f5ba3f9a9c61df76602bc6d076ddbc3034d473c0
TürDeğerNot
filepath ff0730a8693c2dea990402e8f5ba3f9a9c61df76602bc6d076ddbc3034d473c0 PDB

C2 Sunucuları (Bu aile için 8 kayıtlı sunucu)

Adres Tip Port Protokol Durum Ülke
95.217.35.154 ip 443 HTTPS inactive FI
upd5.pro domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
metasta.me domain 443 HTTPS inactive —
upd5.pro domain 443 HTTPS inactive —
amacey.com domain 443 HTTPS inactive —
181.174.165.208 ip 443 HTTPS sinkholed AR
212.117.180.232 ip 443 HTTPS sinkholed CH

C2 adresleri yalnızca KEYDAL ekibinin manuel olarak doğruladığı malware örnekleri üzerinden sunulmaktadır. Ticari amaçla kullanılamaz.

Etiketler
1677490643BB17dllQakbotQuakbot