3.2.rundll32.exe.3100000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
3.2.rundll32.exe.3100000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
3.2.rundll32.exe.3100000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.3.regsvr32.exe.2cce488.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.3.regsvr32.exe.2cce488.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0xf76c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.3.regsvr32.exe.2cce488.1.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.3.regsvr32.exe.2cce488.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1aa14:$a4: %u;%u;%u;
- 0x1af50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1add8:$a6: %u&%s&%u
- 0x746d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x77ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x1ad9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x1531:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xb0ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
18.2.explorer.exe.2f80000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
18.2.explorer.exe.2f80000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
18.2.explorer.exe.2f80000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.3.regsvr32.exe.2cce488.1.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0xf76c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.3.regsvr32.exe.2cce488.1.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1aa14:$a4: %u;%u;%u;
- 0x1af50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1add8:$a6: %u&%s&%u
- 0x746d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x77ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x1ad9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x1531:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xb0ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.2.regsvr32.exe.27a0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.2.regsvr32.exe.27a0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.2.regsvr32.exe.27a0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
20.0.explorer.exe.26f0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
20.0.explorer.exe.26f0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
20.0.explorer.exe.26f0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
4.2.rundll32.exe.2eb0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
4.2.rundll32.exe.2eb0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
4.2.rundll32.exe.2eb0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.3.regsvr32.exe.2cce488.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.3.regsvr32.exe.2cce488.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.3.regsvr32.exe.2cce488.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
4.2.rundll32.exe.2eb0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
4.2.rundll32.exe.2eb0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
4.2.rundll32.exe.2eb0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
22.0.explorer.exe.2ed0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
22.0.explorer.exe.2ed0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
22.0.explorer.exe.2ed0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
18.0.explorer.exe.2f80000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
18.0.explorer.exe.2f80000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
18.0.explorer.exe.2f80000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
19.2.explorer.exe.2e20000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
19.2.explorer.exe.2e20000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
19.2.explorer.exe.2e20000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
3.2.rundll32.exe.3100000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
3.2.rundll32.exe.3100000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
3.2.rundll32.exe.3100000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
22.0.explorer.exe.2ed0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
22.0.explorer.exe.2ed0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
22.0.explorer.exe.2ed0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
19.2.explorer.exe.2e20000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
19.2.explorer.exe.2e20000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
19.2.explorer.exe.2e20000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
19.0.explorer.exe.2e20000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
19.0.explorer.exe.2e20000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
19.0.explorer.exe.2e20000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
22.2.explorer.exe.2ed0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
22.2.explorer.exe.2ed0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
22.2.explorer.exe.2ed0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
0.2.loaddll32.exe.a20000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
0.2.loaddll32.exe.a20000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
0.2.loaddll32.exe.a20000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
18.2.explorer.exe.2f80000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
18.2.explorer.exe.2f80000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
18.2.explorer.exe.2f80000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.3.regsvr32.exe.2cce488.1.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.3.regsvr32.exe.2cce488.1.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.3.regsvr32.exe.2cce488.1.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
20.2.explorer.exe.26f0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
20.2.explorer.exe.26f0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
20.2.explorer.exe.26f0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
19.0.explorer.exe.2e20000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
19.0.explorer.exe.2e20000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
19.0.explorer.exe.2e20000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
2.2.regsvr32.exe.27a0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
20.2.explorer.exe.26f0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
2.2.regsvr32.exe.27a0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
2.2.regsvr32.exe.27a0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
20.2.explorer.exe.26f0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
20.2.explorer.exe.26f0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
18.0.explorer.exe.2f80000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
18.0.explorer.exe.2f80000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
18.0.explorer.exe.2f80000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
20.0.explorer.exe.26f0000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
20.0.explorer.exe.26f0000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
20.0.explorer.exe.26f0000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
22.2.explorer.exe.2ed0000.0.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
22.2.explorer.exe.2ed0000.0.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x1036c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
22.2.explorer.exe.2ed0000.0.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ba14:$a4: %u;%u;%u;
- 0x1bf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1bdd8:$a6: %u&%s&%u
- 0x806d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x83ab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x26d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2131:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xbcff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
0.2.loaddll32.exe.a20000.0.raw.unpack | JoeSecurity_Qbot_1 | Yara detected Qbot | Joe Security | |
0.2.loaddll32.exe.a20000.0.raw.unpack | Windows_Trojan_Qbot_92c67a6d | unknown | unknown | - 0x10f6c:$a: 33 C0 59 85 F6 74 2D 83 66 0C 00 40 89 06 6A 20 89 46 04 C7 46 08 08 00
|
0.2.loaddll32.exe.a20000.0.raw.unpack | Windows_Trojan_Qbot_3074a8d4 | unknown | unknown | - 0x1ca14:$a4: %u;%u;%u;
- 0x1cf50:$a5: %u.%u.%u.%u.%u.%u.%04x
- 0x1cdd8:$a6: %u&%s&%u
- 0x8c6d:$get_string1: 33 D2 8B C6 6A 5A 5F F7 F7 8B 7D 08 8A 04 3A 8B 55 F8 8B 7D 10 3A 04 16
- 0x8fab:$set_key: 8D 87 00 04 00 00 50 56 E8 22 16 00 00 59 8B D0 8B CE E8
- 0x32d9:$do_computer_use_russian_like_keyboard: B9 FF 03 00 00 66 23 C1 33 C9 0F B7 F8 66 3B 7C 4D
- 0x2d31:$execute_each_tasks: 8B 44 0E 0C 85 C0 74 04 FF D0 EB 12 6A 00 6A 00 6A 00 FF 74 0E 08 E8 22 F0 FF FF 83 C4 10
- 0xc8ff:$generate_random_alpha_num_string: 57 E8 D5 DC FF FF 48 50 8D 85 30 F6 FF FF 6A 00 50 E8 DD 6D 00 00 8B 4D F8 83 C4 10 8A 04 38 88 04 0E 46 83 FE 0C
|
Click to see the 79 entries |