2021-02-12 (FRIDAY) - QAKBOT (QBOT) INFECTION WITH COBALT STRIKE

NOTICE:

ASSOCIATED FILES:

  • 2021-02-12-IOCs-for-Qakbot-with-Cobalt-Strike.txt   (2,628 bytes)
  • 2021-02-12-Qakbot-malspam-French-language-1611-UTC.eml   (448,665 bytes)
  • 2021-02-12-Qakbot-infection-with-Cobalt-Strike.pcap   (39,542,354 bytes)
  • directly (76).xls   (325,632 bytes)
  • kdfe.vbox   (473,600 bytes)

 

IMAGES

 


Shown above:  Traffic from the infection filtered in Wireshark showing Qakbot infection activity.

 


Shown above:  Traffic from the infection filtered in Wireshark showing Cobalt Strike caused by the Qakbot infection.

 


Shown above:  More Cobalt Strike on the same IP address but using "www.amazon.com" as the domain (NOTE: this is not actually amazon.com).

 

Click here to return to the main page.