Qbot, a Windows-based banking trojan malware that has been active since 2008, makes a strong return with new features. Qbot, also known as Qakbot and Pinkslipbot, targets banks and financial institutions mainly. Qbot operators generally attack their victims through phishing campaigns and inject the malware using a dropper. Their main motive is to collect details about browsing activity, steal bank account credentials and other financial information.
Previously, Qbot used a self-replicating worm to copy itself over shared and removable media. After the latest updates Qbot malware has added both detection and research-evasion techniques with features to hide the code from the scanner and other signature-based tools. In addition, to bypass forensic investigation it comes with built in anti-virtual machine techniques.[/vc_wp_text][vc_wp_text]
Infection and Propagation Vector
- Qbot malware is loaded into the running explorer.exe memory from an executable file that is distributed via phishing emails or an open file share.
- The malware then installs itself onto the application folder’s default location, as defined in the %APPDATA% registry key.
- Qbot creates a copy of itself in the specific registry key.
- HKCU\Software\Microsoft\Windows\CurrentVersion\Run to run when the system reboots
- Then, it drops a .dat file with a log of the system information and the botnet name.
- The malware executes its copy from the %APPDATA% folder and replaces the originally infected file with a legitimate one.
- Finally, Qbot creates an instance of explorer.exe and injects itself into it. Hackers then use the always-running explorer.exe process to update Qbot from their external command-and-control server.
Key features
- Steal users’ keystrokes,
- Deploy backdoors,
- Spread malware payloads on compromised devices.
Indicators of Compromise
- 432B6D767539FD5065593B160128AA7DCE271799AD2088A82A16542E37AD92B0
- D3B38681DBC87049022A3F33C9888D53713E144A277A7B825CF8D9628B9CA898
- 9001DF2C853B4BA118433DD83C17617E7AA368B1
- 449F2B10320115E98B182204A4376DDC669E1369
- F85A63CB462B8FD60DA35807C63CD13226907901
- B4BC69FF502AECB4BBC2FB9A3DFC0CA8CF99BA9E
- 1AAA14A50C3C3F65269265C30D8AA05AD8695B1B
- 577522512506487C63A372BBDA77BE966C23CBD1
- 75107AEE398EED78532652B462B77AE6FB576198
- 674685F3EC24C72458EDC11CF4F135E445B4185B
- BECD8F2D6289B51981F07D5FF52916104D764DD5
- 18E8971B2DE8EA3F8BB7E1462E414DA936425D4E
- 4C96D2BCE0E12F8591999D4E00498BCDB8A116DE
- 571cdef12082946e34b77bd50fcb0d38
- 06ec0af8411d864211baff8afb117f72
- 2d2fa093dd4fb26a8d14f1906552d238
- 842d7815923dffc1e1cf2ebbcd0fdf49
- 2e4c99684fc0046934b984268b16c25b
- hxxp://w1.plenimusic[.]com/fakes/
- hxxp://pickap[.]io/wp-content/uploads/2020/04/evolving/888888.png
- hxxp://decons[.]vn/wp-content/uploads/2020/04/evolving/888888.png
- hxxp://econspiracy[.]se/evolving/888888.png
- hxxp://enlightened-education[.]com/wp-content/uploads/2020/04/evolving/888888.png
- hxxp://kslanrung[.]com/evolving/888888.png
- hxxps://82.118.22[.]125/bgate
Impact
The key features of this malware can help Qbot:- Capture keystrokes and gather details such as usernames, passwords, financial details like credit card information.
- These details can be used for social engineering tactics to further the criminals’ agenda.
- Create a backdoor which helps to access the user’s device.
Mitigations
- Use updated antivirus software to detect and stop malware infections.
- Apply critical patches to the system and application.
- Inspect encrypted traffic; most malware and phishing sites are pushed within encrypted SSL/TLS sessions.
- User Awareness makes it easy for them to report suspicious behavior.
- Back-up data regularly