2022-06-27 (MONDAY) - OBAMA194 QAKBOT (QBOT) WITH DARK CAT VNC AND COBALT STRIKE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- I've mistakenly reported the Dark Cat VNC traffic here as "DarkVNC" in previous versions of this post.
- I've fixed this blog post and the material to show the correct activity.
- For more on Dark Cat VNC, see: https://blog.nviso.eu/2023/03/20/icedids-vnc-backdoors-dark-cat-anubis-keyhole/
REFERENCE:
ASSOCIATED FILES:
- 2022-06-27-IOCs-for-obama194-Qakbot-infection-with-Cobalt-Strike-and-Dark-Cat-VNC.txt.zip 1.6 kB (1,610 bytes)
- 2022-06-27-obama194-Qakbot-malspam-1934-UTC.eml.zip 7.2 kB (7,240 bytes)
- 2022-06-27-obama194-Qakbot-malware-and-artifacts.zip 674 kB (673,551 bytes)
- 2022-06-27-part-1-of-2-Qakbot-with-Cobalt-Strike-and-Dark-Cat-VNC.pcap.zip 7.3 MB (7,331,266 bytes)
- 2022-06-27-part-2-of-2-Qakbot-with-Dark-Cat-VNC-and-email-banner-traffic.pcap.zip 11.0 MB (11,033,431 bytes)
IMAGES
Shown above: Screenshot of video from the decoded VNC traffic.
Click here to return to the main page.