371 Followers
31 Following
32 Posts
Incident Response & Malware Hunter
MalwareBazaar | Checking your browser

MalwareBazaar | Checking your browser

#Qakbot - BB11 - url > .zip > .iso > .wsf > .dll

wscript.exe GR1.wsf

rundll32.exe C:\ProgramData\user.dat,Updt

net view

cmd /c set

arp -a

ipconfig /all

nslookup -querytype=ALL -timeout=12 _ldap._tcp.dc._msdcs.WORKGROUP

net share

net1 share

route print

netstat -nao

net localgroup

net1 localgroup

whoami /all

Samples πŸ‘‡

https://bazaar.abuse.ch/sample/1883a9b94e11a3db9aa0cd29d7864af6e45d93fb7f5c873b8256d36e648a289f/

https://bazaar.abuse.ch/sample/845900fb58adf3e8b086c9517dfc5deeaefb5e6be80606b8e93c21502d2fe44c/

IOC's
https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_BB11_22.12.2022.txt

MalwareBazaar | Checking your browser

#Qakbot - azd - .html > .zip > .img > .lnk > .cmd > .dll

cmd /c SCAN_SP0692.lnk

cmd.exe /c Invoice\YouContract.cmd A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 0 1 2 3 4 5 6 7 8 9

rundll32 /s contract.dll,Updt

Sample πŸ‘‡

https://bazaar.abuse.ch/sample/784a2827b5ddc82e69198aa9f6a5382c32716eb0263bc2a4f6fc500589c8a3ef/

https://bazaar.abuse.ch/sample/2a23cae4be2ab6165bd39d1af410be71df04f883b25dafb71d516d5eb5468da5/

IOC's
https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_azd_22.12.2022.txt

MalwareBazaar | Checking your browser

MalwareBazaar | Checking your browser

MalwareBazaar | Checking your browser

MalwareBazaar | Checking your browser

MalwareBazaar | Checking your browser

#Qakbot - obama225 - .html > .zip > .vhd > .lnk > .cmd > .cmd > .dll

cmd /c C:\Users\User\AppData\Local\Temp\Claim.lnk

cmd.exe /q /c amended\concavity.cmd

cmd.exe /K amended\depressurize.cmd system rundl

replace C:\Windows\\system32\\rundlr32.exe C:\Users\User\AppData\Local\Temp /A

rundll32 amended\\unwarmed.tmp,DrawThemeIcon

Samples πŸ‘‡

https://bazaar.abuse.ch/sample/a6ee266834675fea92b4d1ac2317e79e16dd33939d883a2ba5af2bba3db9872f/

https://bazaar.abuse.ch/sample/4a6fa75896f4dca8e3ad9c5024037b10b61bd4a723819aaf0ea941f37a763411/

IOC's
https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama225_02.12.2022.txt

MalwareBazaar | Checking your browser

#Qakbot - obama224 - html > .zip > .iso > .vbs > .ps1 > .dll

wscript.exe WP.vbs

powershell.exe -ExecutionPolicy Bypass metaphysic\possessively.ps1

rundll32.exe C:\users\public\mercifulHaddock.txt DrawThemeIcon

Samples πŸ‘‡

https://bazaar.abuse.ch/sample/ef43ad2327c74d2ac4343209325b004a15f4f858bb68e871adcca5a320573025/

https://bazaar.abuse.ch/sample/24d7bb336cff00af352ee187d6c215dc037ac3f39ef1936deca18bb3ac472eb7/

IOC's
https://github.com/pr0xylife/Qakbot/blob/main/Qakbot_obama224_30.11.2022.txt

MalwareBazaar | Checking your browser