2022-06-21 (TUESDAY) - "AA" DISTRIBUTION QAKBOT (QBOT) WITH DARK CAT VNC AND COBALT STRIKE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- In the reference below, I mistakenly reported the Dark Cat VNC traffic as "DarkVNC" for @Unit42_Intel.
- I've fixed this blog post and the material to show the correct activity.
- For more on Dark Cat VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
REFERENCE:
ASSOCIATED FILES:
- 2022-06-21-IOCs-for-AA-distribution-Qakbot-with-Dark-Cat-VNC-and-Cobalt-Strike.txt.zip 2.0 kB (1,977 bytes)
- 2022-06-21-AA-Qakbot-with-Dark-Cat-VNC-and-Cobalt-Strike.pcap.zip 79.3 MB (79,266,728 bytes)
- 2022-06-21-Qakbot-malware-and-artifacts.zip 2.0 MB (1,998,414 bytes)
IMAGES
Shown above: Screenshot of video from the decoded VNC traffic.
Click here to return to the main page.