cyber_threat_intelligence/Qakbot
2022-01-31 14:44:46 +01:00
..
README.md Update 2022-01-31 14:44:46 +01:00

Qakbot - Cyber Threat Intelligence

The indicators are related to VulDB CTI analysis of the actor known as Qakbot. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, activities, intentions, emerging research, and attacks. Our unique predictive model is able to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.qakbot

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Qakbot:

  • AU

IOC - Indicator of Compromise

These indicators of compromise indicate associated network ressources which are known to be part of research and attack activities of Qakbot.

ID IP address Hostname Confidence
1 2.7.116.188 lfbn-lyo-1-277-188.w2-7.abo.wanadoo.fr High
2 2.50.47.97 - High
3 5.15.81.52 5-15-81-52.residential.rdsnet.ro High
4 5.193.178.241 - High
5 24.42.14.241 - High
6 24.43.22.221 rrcs-24-43-22-221.west.biz.rr.com High
7 24.55.112.61 dynamic.libertypr.net High
8 24.90.160.91 cpe-24-90-160-91.nyc.res.rr.com High
9 24.95.61.62 cpe-24-95-61-62.columbus.res.rr.com High
10 24.117.107.120 24-117-107-120.cpe.sparklight.net High
11 24.139.72.117 - High
12 24.139.132.70 dynamic.libertypr.net High
13 24.152.219.253 24.152.219.253.res-cmts.sm.ptd.net High
14 24.164.79.147 cpe-24-164-79-147.cinci.res.rr.com High
15 24.165.87.61 cpe-24-165-87-61.san.res.rr.com High
16 24.183.39.93 024-183-039-093.res.spectrum.com High
17 24.202.42.48 modemcable048.42-202-24.mc.videotron.ca High
18 24.226.156.153 24-226-156-153.resi.cgocable.ca High
19 24.229.150.54 24.229.150.54.cmts-static.sm.ptd.net High
20 24.234.86.201 wsip-24-234-86-201.lv.lv.cox.net High
21 27.223.92.142 - High
22 35.142.12.163 035-142-012-163.dhcp.bhn.net High
23 41.34.91.90 host-41.34.91.90.tedata.net High
24 41.97.138.74 - High
25 45.32.211.207 45.32.211.207.vultr.com Medium
26 45.46.53.140 cpe-45-46-53-140.maine.res.rr.com High
27 45.63.107.192 45.63.107.192.vultr.com Medium
28 45.67.231.247 vm272927.pq.hosting High
29 45.77.115.208 45.77.115.208.vultr.com Medium
30 45.77.117.108 45.77.117.108.vultr.com Medium
31 45.77.215.141 45.77.215.141.vultr.com Medium
32 46.214.62.199 46-214-62-199.next-gen.ro High
33 47.22.148.6 ool-2f169406.static.optonline.net High
34 47.24.47.218 047-024-047-218.res.spectrum.com High
35 47.153.115.154 - High
36 47.196.192.184 - High
37 49.207.105.25 broadband.actcorp.in High
38 50.29.166.232 50.29.166.232.res-cmts.sth3.ptd.net High
39 50.104.68.223 50-104-68-223.prtg.in.frontiernet.net High
40 50.244.112.106 50-244-112-106-static.hfc.comcastbusiness.net High
41 59.90.246.200 static.bb.chn.59.90.246.200.bsnl.in High
42 64.19.74.29 primhall.com High
43 64.121.114.87 64-121-114-87.s597.c3-0.smt-ubr1.atw-smt.pa.cable.rcncustomer.com High
44 65.100.174.]105 - High
45 65.100.174.]106 - High
46 65.100.174.]107 - High
47 65.100.174.]108 - High
48 65.100.174.]109 - High
49 65.100.174.]111 - High
50 66.26.160.37 066-026-160-037.inf.spectrum.com High
51 66.57.216.53 rrcs-66-57-216-53.midsouth.biz.rr.com High
52 66.208.105.6 66-208-105-6.centex.net High
53 67.6.12.4 67-6-12-4.clma.centurylink.net High
54 67.8.103.21 67-8-103-21.res.bhn.net High
55 ... ... ...

There are 214 more IOC items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Qakbot. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File /admin/ Low
2 Argument username/password High
3 Input Value 'or''=' Low

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2022 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!