Qakbot Dropper Analysis

In this video we analyze the Qakbot Malware Dropper. The file that starts the infection is an HTML File, the flow is as follows:
- html drops .zip via html smuggling.
- zip contains iso file.
- iso contains .lnk.
- Lnk file launches calc.exe,
- calc.exe sideloads windowscodecs.dll
- windowscodecs.dll executes the malicious payload dll (102755.dll).
Malware Sample: hxxps[://]bazaar[.]abuse[.]ch/sample/f5c16248418a4f1fd8dff438b26b8da7f587b77db9e180a82493bae140893687/
Malware Analysis Course Link: courses.null-char.com/courses...
Academy Link: ask-academy.live/
Please provide feedback in the comments.
To continue the conversation hit me up on twitter:
🐦 Twitter - / nu11charb
#malware #Qakbot #HTMLSmuggling #DLLSideLoading #reverseengineering

Пікірлер: 20

  • @rizwanmehboob4725
    @rizwanmehboob47252 жыл бұрын

    Great analysis as always. Looking forward for part 2 :)

  • @0xca733
    @0xca7332 жыл бұрын

    amazing as always :) thanks for uploading this, hope you are well!

  • @vikalpdutttripathi
    @vikalpdutttripathi2 жыл бұрын

    Nice explanation. Thank you for sharing!

  • @dsosa23
    @dsosa232 жыл бұрын

    Great video. I wish there was a course for beginners on how to do this. So helpful.

  • @ahmedskasmani

    @ahmedskasmani

    2 жыл бұрын

    There is a Malware Analysis course by me on how do this. Check the description there is link for my course.

  • @MalwareHunter_07
    @MalwareHunter_07Ай бұрын

    hey great explanation but i wanted to know whats the final payload dll have impact on the system? or just a sideloading

  • @Dchmielewski09
    @Dchmielewski09 Жыл бұрын

    Thanks for the video, great job!

  • @ahmedskasmani

    @ahmedskasmani

    Жыл бұрын

    You are most welcome

  • @0fzex003
    @0fzex003 Жыл бұрын

    keep going great explanation

  • @ahmedskasmani

    @ahmedskasmani

    Жыл бұрын

    Many thanks

  • @hindimoviesindia3477
    @hindimoviesindia34772 жыл бұрын

    Thanks Bruu

  • @c3rb3ru5d3d53c
    @c3rb3ru5d3d53c Жыл бұрын

    Great video!

  • @ahmedskasmani

    @ahmedskasmani

    Жыл бұрын

    Thanks a lot legend 🙂

  • @ahmedhassane2369
    @ahmedhassane2369 Жыл бұрын

    شكرآ ا تحليل جيد

  • @MakkiMohammedymailcom
    @MakkiMohammedymailcom2 жыл бұрын

    thank you good sir

  • @Giscardyoryor
    @Giscardyoryor2 жыл бұрын

    Genius!!

  • @jilinmr3092
    @jilinmr3092 Жыл бұрын

    Hi ahmed, how can we perform the analysis on .dat file instaed of calc.exe. New qakbot are coming .dat file inside the ISO image

  • @dawidp7094
    @dawidp70942 жыл бұрын

    Are there any chances for zuorat malware analysis Sir?

  • @cybercdh
    @cybercdh2 жыл бұрын

    Nice video!

  • @ahmedskasmani

    @ahmedskasmani

    2 жыл бұрын

    Thanks Colin