2022-06-07 (TUESDAY) OBAMA186 DISTRIBUTION QAKBOT (QBOT) INFECTION WITH DARK CAT VNC AND SPAMBOT ACTIVITY
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- I have mistakenly reported the Dark Cat VNC traffic here as "DarkVNC" in a previous version of this blog post.
- I've fixed this blog post and the material to show the correct activity.
- For more on Dark Cat VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
ASSOCIATED FILES:
- 2022-06-07-IOCs-for-obama186-Qakbot-with-Dark-Cat-VNC-traffic.txt.zip 3.9 kB (3,892 bytes)
- 2022-06-07-Qakbot-obama186-malspam-11-examples.zip 10.0 MB (10,028,625 bytes)
- 2022-06-07-obama186-Qakbot-infection-with-Dark-Cat-VNC-and-spambot-traffic.pcap.zip 33.1 MB (33,088,102 bytes)
- 2022-06-07-obama186-Qakbot-malware-and-artifacts.zip 33.1 MB (33,145,385 bytes)
IMAGES
Shown above: Screenshot of video from the decoded VNC traffic.
Click here to return to the main page.