Qakbot Dropper Analysis

Sdílet
Vložit
  • čas přidán 21. 08. 2024
  • In this video we analyze the Qakbot Malware Dropper. The file that starts the infection is an HTML File, the flow is as follows:
    - html drops .zip via html smuggling.
    - zip contains iso file.
    - iso contains .lnk.
    - Lnk file launches calc.exe,
    - calc.exe sideloads windowscodecs.dll
    - windowscodecs.dll executes the malicious payload dll (102755.dll).
    Malware Sample: hxxps[://]bazaar[.]abuse[.]ch/sample/f5c16248418a4f1fd8dff438b26b8da7f587b77db9e180a82493bae140893687/
    Malware Analysis Course Link: courses.null-c...
    Academy Link: ask-academy.live/
    Please provide feedback in the comments.
    To continue the conversation hit me up on twitter:
    🐦 Twitter - / nu11charb
    #malware #Qakbot #HTMLSmuggling #DLLSideLoading #reverseengineering

Komentáře • 20

  • @rizwanmehboob4725
    @rizwanmehboob4725 Před 2 lety

    Great analysis as always. Looking forward for part 2 :)

  • @dsosa23
    @dsosa23 Před 2 lety

    Great video. I wish there was a course for beginners on how to do this. So helpful.

    • @ahmedskasmani
      @ahmedskasmani  Před 2 lety

      There is a Malware Analysis course by me on how do this. Check the description there is link for my course.

  • @0xca733
    @0xca733 Před 2 lety

    amazing as always :) thanks for uploading this, hope you are well!

  • @0fzex003
    @0fzex003 Před rokem

    keep going great explanation

  • @vikalpdutttripathi
    @vikalpdutttripathi Před 2 lety

    Nice explanation. Thank you for sharing!

  • @MakkiMohammedymailcom
    @MakkiMohammedymailcom Před 2 lety

    thank you good sir

  • @c3rb3ru5d3d53c
    @c3rb3ru5d3d53c Před rokem

    Great video!

  • @MalwareHunter_07
    @MalwareHunter_07 Před 2 měsíci

    hey great explanation but i wanted to know whats the final payload dll have impact on the system? or just a sideloading

  • @ahmedhassane2369
    @ahmedhassane2369 Před rokem

    شكرآ ا تحليل جيد

  • @Dchmielewski09
    @Dchmielewski09 Před rokem

    Thanks for the video, great job!

  • @hindimoviesindia3477
    @hindimoviesindia3477 Před 2 lety

    Thanks Bruu

  • @Giscardyoryor
    @Giscardyoryor Před 2 lety

    Genius!!

  • @cybercdh
    @cybercdh Před 2 lety

    Nice video!

  • @jilinmr3092
    @jilinmr3092 Před rokem

    Hi ahmed, how can we perform the analysis on .dat file instaed of calc.exe. New qakbot are coming .dat file inside the ISO image

  • @dawidp7094
    @dawidp7094 Před 2 lety

    Are there any chances for zuorat malware analysis Sir?