Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-08-03 (MONDAY) - QAKBOT (QBOT) SPX147
- NOTES:
- - Qakbot is back to spamming today, the first time since 2020-06-23 (spx146)
- REFERENCES:
- - https://twitter.com/mesa_matt/status/1290315727912738816
- - https://twitter.com/lazyactivist192/status/1290321073997860868
- - https://pastebin.com/gWxajTRN
- - https://www.malware-traffic-analysis.net/2020/08/03/index.html
- 34 EXAMPLES OF URLS FROM MALSPAM TO DOWNLOAD THE INITIAL ZIP ARCHIVE:
- - hxxp://acaimaniaecia.acaimenu[.]com/gmpqqeevpkab/Ht/WC/a4Rnasoi.zip
- - hxxp://alldgm[.]in/ubmrbyhjxtgf/9r/vh/Ca9h34GN.zip
- - hxxp://alldgm[.]in/ubmrbyhjxtgf/ou/7H/DkHgYqzW.zip
- - hxxp://alldgm[.]in/ubmrbyhjxtgf/WsHyx7T7L6.zip
- - hxxp://allthingstravel[.]co[.]uk/vrimncsnfh/c/P9cQaB6w1.zip
- - hxxp://arssilim[.]com/gotbolkwgk/FkbbS6QT6b.zip
- - hxxp://bilal.newtechnologyxperts[.]com/xlzlwbn/jDXcgdjyB4.zip
- - hxxp://bridalmasks[.]com/ifhbij/9h/QS/kwdpaes6.zip
- - hxxp://bridalmasks[.]com/ifhbij/FOzD8nfKgO.zip
- - hxxp://correctordeortografia[.]com/ygamaikfr/e/aIudlGY31.zip
- - hxxp://correctordeortografia[.]com/ygamaikfr/Io/XW/dN7PA9Mn.zip
- - hxxp://dca.district9211[.]org/ahgrxqesc/pzjsD3bbYo.zip
- - hxxp://dca.district9211[.]org/ahgrxqesc/S/Z1HzZBxmm.zip
- - hxxp://dehkadehzaferan[.]com/vkahlrwruo/9/y6weCEdm4.zip
- - hxxp://diamondbraintutor[.]com/yucsomjbz/gE/NI/sq1RHXCO.zip
- - hxxp://digitalservicecare[.]in/pzdggpg/iu/3g/w5evoSA6.zip
- - hxxp://escuelajosesanabria[.]com/dpfpfl/2c/zM/eVUfmt02.zip
- - hxxp://findthemlocal[.]co[.]uk/bbhgt/w/rz6Pok2I4.zip
- - hxxp://gartengestaltung-hoellerer[.]de/fnfttgll/GRAKA0qxNw.zip
- - hxxp://gofaststrap[.]com/cbiacoah/y9/Ps/MfuPLZLK.zip
- - hxxp://itc-sr[.]ru/iozipuqbw/5hYQTPaxwI.zip
- - hxxp://izi-jobs[.]net/qslbf/hB/GF/byiKCv7U.zip
- - hxxp://kalamelk[.]ir/ikyevsry/4f0Nr7EsFc.zip
- - hxxp://learntus[.]co[.]in/vadisbbvn/w79cc9nfiI.zip
- - hxxp://m.exoticcarrentalorlando[.]com/waqkvdyhl/a/FrQxzjviN.zip
- - hxxp://paarcell[.]com/whxutsxylnos/I/HgdVnXLbX.zip
- - hxxp://pslrn.com[.]br/jfjmtdy/UC/m5/L6YFAxZa.zip
- - hxxp://sharkbum[.]com/njwbnb/rKiPJCuwZM.zip
- - hxxp://startseunegocio[.]com/exwtz/p/LzCYqITKk.zip
- - hxxp://vitinhphamgia[.]com/pcjynxvxwr/ly/Lt/lSR9GDFV.zip
- - hxxp://www.mira-blau[.]de/oubkdxb/gBi4l66lrI.zip
- - hxxp://www.officeautomationltd[.]com/njghv/K/bqVDeP9hU.zip
- - hxxp://www.sportingpro[.]com[.]ar/vicldxvutk/HA/pG/21wGqfI9.zip
- - hxxp://xltc-dta[.]be/hwpaz/j/H9pJyYiax.zip
- 5 EXAMPLES OF THE INITIAL ZIP ARCHIVE:
- - 6258d0ffd544a3ff02fd74d162c6e1aab40a44d4a2b7447970374f9f4ca29ac9 21wGqfI9.zip
- - 9bc92658cc86ca82be3881fb21eaa840a111c024cd65ce7d8630653bc2256866 aIudlGY31.zip
- - 5cfd15470a434f048d29051ce733cae8063479d706e2b6156d4dfaddef386894 byiKCv7U.zip
- - fc5702b536d817baa13dedcc80b280c74453c845b4d713f13ae6ff2325a97ff5 jDXcgdjyB4.zip
- - bff02c0926e6d805c7f6324c4a0cdc8b68df253d2181f22296fa8baf483d3fcd pzjsD3bbYo.zip
- 5 EXAMPLES OF EXTRACTED VBS FILES:
- - f7eebe0b84ebcf549c278263c83944bb3adcedc16e5d5488309d2de426040c38 PH1917019.vbs
- - ee02d31a24d420570fd9bb5d8a9ae09505db317562137c0938ac173c23d0271d PH2987153.vbs
- - 2ea11e59848878d6af8d0318fb2f23e7f445a98aedf1be0f4d6ac9e3a5dc4c0f PH3497638.vbs
- - 029aecca7652215a52c2de9e4c914867bfe4899914169696068c7c39515ef027 PH4318217.vbs
- - 8def7a6f1f6dea6c73a22504b0b79c51fcc329fa68e6408f678270e8908f405d PH6580048.vbs
- 6 URLS FOR THE QAKBOT SPX147 EXE:
- - hxxp://ttt.s-host[.]net/heaqwhmudzc/8888888.png
- - hxxp://izi-jobs[.]re/zklvxtelxlw/8888888.png
- - hxxp://astamvillagelodge[.]com/rbntjp/8888888.png
- - hxxp://fresh-organic-food[.]com/ddpauqvq/8888888.png
- - hxxp://fareapp[.]com[.]br/ffvbpqjsjfwp/8888888.png
- - hxxp://frenchsporting[.]bts2020[.]fr/nwgjc/8888888.png
- QAKBOT SPX147 EXE INITIALLY SAVED TO:
- - C:\Users\[username]\AppData\Local\Temp\Direct3DMX.exe
- 5 EXAMPLES OF QAKBOT SPX147 EXE:
- - 0636479f9f0ae8ad2c4288da3aad038bc69977674a18afbd52d43cc7b9931f74
- - 0930678a148689d3b2eab8f68acb2b8b857375a97e1701505c347ae30848dd6a
- - 342ac51b292bbd8185b2c6fc44b343a5e6d7a45af5398847434f00092cddf2ad
- - 6a41a49bfe9db6c5b638d4438dbf7c84451a22b74f2c0f7a5e6f7a034712c1da
- - a330e49a6bb1ccc8c05de0e241f4faf2b15a2d4dd004301c3320a597347b5e5f
- EXAMPLE OF QAKBOT SPX147 EXE PERSISTENT ON AN INFECTED WINDOWS HOST:
- - Resitry Key Name: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- - Value Name: ehjsqfs
- - Value Type: REG_SZ
- - Value Data: "C:\Users\[username]\AppData\Roaming\Microsoft\Xjzpf\eidfii.exe"
- TRAFFIC FROM AN INFECTED WINDOWS 10 HOST:
- - 107.180.91[.]64 port 80 - correctordeortografia[.]com - GET /ygamaikfr/e/aIudlGY31.zip
- - 185.253.219[.]218 port 80 - ttt.s-host[.]net - GET /heaqwhmudzc/8888888.png
- - 24.136.34[.]71 port 2222 - attempted TCP connections, but no response from the server
- - 35.209.218[.]146 port 443 - HTTPS traffic
- - 82.118.22[.]125 port 443 - HTTPS traffic
- - 54.36.108[.]120 port 65400 - TCP traffic
- - port 443 - cdn.speedof[.]me - HTTPS traffic (not inherently malicious)
- - port 443 - api.ipify[.]org - IP address check (not inherently malicious
- - 89.105.198[.]119 port 80 - a.strandsglobal[.]com - GET /redir_chrome.html
- - 89.105.198[.]119 port 80 - a.strandsglobal[.]com - GET /redir_ff.html
- - 89.105.198[.]119 port 80 - a.strandsglobal[.]com - GET /redir_ie.html
- - various IP addresses over various ports - spambot activity from the Qakbot-infected host
- - 109.234.161[.]51 port 80 - izi-services[.]re - POST /vds.php
- - 35.213.169[.]136 port 80 - pattayafootball[.]com - POST /vds.php
- - 107.180.40[.]62 port 80 - bridalmasks[.]com - POST /vds.php
- - 112.213.89[.]168 port 80 - gymhub[.]vn - POST /vds.php
- - 152.32.211[.]197 port 80 - phpyb[.]com - POST /vds.php
- - 152.32.211[.]197 port 80 - phpyb[.]com - GET /tryxf/test.zip
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement