IOC Radar

Indicators are what attackers leave behind. Stolen credentials are what they arrive with.

Check Your Exposure
TLP:WHITE7 IOCs

Qbot: A Deep Dive into the Banking Trojan

AF
Aziz Farghly
Published June 26, 2023Original Report

Threat Actors

Malware Families

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYPlayINFRASTRUCTUREhttp://pickap.io/wp-c…http://kslanrung.com/…http://enlightened-ed…CAPABILITYPlayQakBotVICTIMunknown
Adversary(1)
Infrastructure(5)
Capability(2)
Victim

Indicators of Compromise

Indicators of Compromise7

TypeIndicatorConfidenceScoreFirst Seen
URLhttp://pickap.io/wp-content/uploads/2020/04/evolving/888888.png
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://kslanrung.com/evolving/888888.png
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256f5ff6dbf5206cc2db098b41f5af14303f6dc43e36c5ec02604a50d5cfecf4790
exfiltrationexploitfile-hash
Medium
53
Oct 9, 26
URLhttp://enlightened-education.com/wpcontent/uploads/2020/04/evolving/888888.png
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://econspiracy.se/evolving/888888.png
intel-blogmalwarenetwork
High
58
Oct 9, 26
URLhttp://decons.vn/wp-content/uploads/2020/04/evolving/888888.png
intel-blogmalwarenetwork
High
58
Oct 9, 26
SHA256118fc3d93d6e34b8f1a817313e218a3a4f5baf996e03cd2be34e237b197fa0f3
exploitfile-hashintel-blog
Medium
53
Oct 9, 26

IOC Relationship Graph

IOC Relationship Graph7 total IOCs
URLSHA256
URL5SHA2562Actors1Malware2REPORTQbot: A Deep Dive into thePlayPlayQakBot
scroll to zoom · drag to pan · click IOC to open