Qakbot
QakBot, also known as Qbot, is a sophisticated and notorious banking trojan and information-stealing malware that has been active since around 2008. Over the years, it has evolved and gained new capabilities, making it a potent threat in the realm of cybercrime. QakBot primarily targets Windows operating systems and is designed to compromise sensitive information, particularly financial data and login credentials.
Target OS
- Windows XP to Windows 11, both 32-64 bit, including Server editions.
Infection Vector
The targets reported receiving emails claiming to be from an IRS employee in latest campaign identified by Microsoft on 11 Dec 2023 on Twitter , which included a PDF attachment.The PDF contained a web link that triggered the download of a digitally signed Windows Installer (.msi) file. When the recipients executed the MSI file, it initiated the QakBot malware through the execution of an embedded DLL using the 'hvsi' export. This technique allows the malware to be invoked, posing a significant threat to the security of the affected systems.
Identification
- C2 Communication
- "78.46.200[.]68"
- 65.108.218[.]24
- Behavior
- "https://85.209.11[.]185:8443/teorema505"
- "C:\Users\user\AppData\Roaming\KROST.dll"
- Strings
- "teorema505"
MITRE ATT&CK
- T1027 - Obfuscated Files or Information
- T1036 - Masquerading
- T1112 - Modify Registry
- T1566 - Spear Phishing
Evasion techniques
- Email LURE with PDF Attachment - Qakbot use lure email with attachment for it's spear phishing mail.
- Obfuscated Files or Information - Qakbot Utilizing AES Encryption for network communication, the system sends secure POST requests to the "/teorema505" in path.
IOC's
- Hash
- 88bbf2a743baaf81f7a312be61f90d76
- 723dae8ed3f157e40635681f028328e6
- C2
- 78.46.200[.]68
- 95.215.108[.]29
- 85.209.11[.]185:8443
- 65.108.218[.]24
- 45.138.74[.]191

Comments
Post a Comment