QakBot C2 Traffic
Tags
attack-pattern: | Malware - T1587.001 Malware - T1588.001 Connection Proxy - T1090 |
Common Information
Type | Value |
---|---|
UUID | 76271e33-6444-47d5-9609-0980ee01a69c |
Fingerprint | 66effb71c0a95372 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | March 2, 2023, 12:43 p.m. |
Added to db | Aug. 12, 2023, 8:16 a.m. |
Last updated | Nov. 15, 2024, 3:46 a.m. |
Headline | UNKNOWN |
Title | QakBot C2 Traffic |
Detected Hints/Tags/Attributes | 13/1/13 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://www.netresec.com/?page=Blog&month=2023-03&post=QakBot-C2-Traffic |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 341 | ✔ | NETRESEC Network Security Blog | https://www.netresec.com/rss.ashx | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 88 | malware-traffic-analysis.net |
|
Details | Domain | 2 | meieou.info |
|
Details | Domain | 2 | gifts.com |
|
Details | File | 1 | meieou.inf |
|
Details | md5 | 23 | 72a589da586844d7f0818ce684948eea |
|
Details | md5 | 16 | ec74a5c51106f0419184d0dd08fb05bc |
|
Details | md5 | 1 | fd4bc6cea4877646ccd62f0792ec0b62 |
|
Details | sha1 | 1 | 9de2a1c39fbe1952221c4b78b8d21dc3afe53a3e |
|
Details | sha1 | 1 | 0c7a37f55a0b0961c96412562dd0cf0b0b867d37 |
|
Details | sha1 | 1 | 22e5446e82b3e46da34b5ebce6de5751664fb867 |
|
Details | IPv4 | 1 | 80.47.61.240 |
|
Details | IPv4 | 1 | 185.80.53.210 |
|
Details | IPv4 | 4 | 23.111.114.52 |