#Qakbot - BB07 - url > .zip > .zip > .iso > .js > .dll
wscript.exe C:\Users\**\AppData\Local\Temp\JG.js
regsvr32.exe almond\lemur.temp
Samples 👇
https://bazaar.abuse.ch/sample/a977ba1c34215867748e450f5323ec6938f45e532b756f9c623e448670d0aa2b/
https://bazaar.abuse.ch/sample/3b00174d5b42adf5da7fe896ce8baae14d67c52f79c49eed82bdf87e3a28d625/
https://bazaar.abuse.ch/sample/3c0c4314624497645c426ed6e9fbfd37042f7aceb51e60a894135ea4a42851c0/
IOC's
https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB07_21.11.2022.txt