Dosya Kimliği
| SHA256 | cbac0399ba98483b366296b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
|---|---|
| Dosya Adı | Document27552.xlsb (Excel Binary Workbook) |
| Boyut | 366.296 byte |
| String Sayisi | 1.628 |
GIF Dosyası Olarak C2 — Polonya Sitesi Ele Geçirme
http://skifashion.pl/ds/161120.gif -- skifashion.pl = meşru Polonya kayak/moda sitesi (HACKED) -- 161120.gif = görüntü değil, PE/shellcode payload! -- Firewall whitelist bypass: .pl domain + .gif uzantısı
C2 Sunucuları
metasta.me -- .me TLD Qakbot C2 OCp3.li -- .li (Liechtenstein TLD) C2 MV C2 -- Config fragment
Qakbot Hakkında
Qakbot (QBot/Quakbot/Pinkslipbot), 2007'den beri aktif finansal trojan ve botnet altyapısıdır. 2023'te FBI "Operation Duck Hunt" operasyonuyla çökertilmiş, ancak 2024'te yeniden aktif olduğu gözlemlendi. E-posta thread hijacking, Excel makroları ve XLSB dosyaları kullanır. Cobalt Strike ve BlackBasta ransomware için dropper görevi yapar.
IOC
| SHA256 | cbac0399ba98483b366296b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
|---|---|
| GIF C2 | skifashion.pl/ds/161120.gif (hacked Polonya sitesi) |
| C2 | metasta.me, OCp3.li |
QakBot — Malware Profile
QakBot Quakbot banker. Notesvb.msi delivery. Named pipe IPC. Modular architecture.
Technical Details
QakBot (Qbot/QuakBot) is a banking trojan and loader active since 2007. Features: credential theft, email hijacking for thread hijacking attacks, lateral movement via SMB/psexec, web injection for banking fraud. Delivered via malspam using hijacked email threads (reply-chain attacks). Modules: email collector, credential grabber, network scanner, VNC plugin. Used to deliver Egregor, ProLock, REvil, Black Basta ransomware. FBI "Operation Duck Hunt" disrupted infrastructure August 2023, removing QakBot from 700,000+ infected machines. Attempted comeback Q4 2023 with new delivery methods.
Attribution / Threat Actor
Gold Lagoon, TA570 (Shatak)
Capabilities & Behavior
IOC List (1 indicators)
# SHA256
cbac0399ba98483b366296b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5
| Type | Value | Note |
|---|---|---|
| sha256 | cbac0399ba98483b366296b3c5a4f7d0e2b6c9f1a3d6e8b1c4f7a0d3e6b9c2f5 |
C2 Servers (8 recorded servers for this family)
| Address | Type | Port | Protocol | Status | Country |
|---|---|---|---|---|---|
| 95.217.35.154 | ip | 443 | HTTPS | inactive | FI |
| upd5.pro | domain | 443 | HTTPS | inactive | — |
| upd5.pro | domain | 443 | HTTPS | inactive | — |
| metasta.me | domain | 443 | HTTPS | inactive | — |
| upd5.pro | domain | 443 | HTTPS | inactive | — |
| amacey.com | domain | 443 | HTTPS | inactive | — |
| 181.174.165.208 | ip | 443 | HTTPS | sinkholed | AR |
| 212.117.180.232 | ip | 443 | HTTPS | sinkholed | CH |
C2 addresses are provided only from malware samples manually verified by the KEYDAL team. Commercial use is prohibited.