cyber_threat_intelligence/actors/Qakbot/README.md
2022-06-28 10:28:01 +02:00

18 KiB

Qakbot - Cyber Threat Intelligence

These indicators were reported, collected, and generated during the VulDB CTI analysis of the actor known as Qakbot. The activity monitoring correlates data from social media, forums, chat rooms, and darknet markets. It helps to determine associated actors, specific activities, expected intentions, emerging research, and ongoing attacks. Our unique predictive model uses big data to forecast activities and their characteristics.

Live data and more analysis capabilities are available at https://vuldb.com/?actor.qakbot

Countries

These countries are directly (e.g. origin of attacks) or indirectly (e.g. access by proxy) associated with Qakbot:

There are 7 more country items available. Please use our online service to access the data.

IOC - Indicator of Compromise

These indicators of compromise (IOC) indicate associated network resources which are known to be part of research and attack activities of Qakbot.

ID IP address Hostname Campaign Confidence
1 1.161.101.20 1-161-101-20.dynamic-ip.hinet.net - High
2 2.7.116.188 lfbn-lyo-1-277-188.w2-7.abo.wanadoo.fr - High
3 2.50.47.97 - - High
4 2.50.171.142 - - High
5 2.51.240.61 - - High
6 2.88.186.229 - - High
7 5.12.111.213 5-12-111-213.residential.rdsnet.ro - High
8 5.12.243.211 5-12-243-211.residential.rdsnet.ro - High
9 5.13.74.26 5-13-74-26.residential.rdsnet.ro - High
10 5.13.84.186 5-13-84-186.residential.rdsnet.ro - High
11 5.15.81.52 5-15-81-52.residential.rdsnet.ro - High
12 5.32.41.45 - - High
13 5.136.131.34 - - High
14 5.193.61.212 - - High
15 5.193.178.241 - - High
16 5.203.199.157 5-203-199-157.pat.nym.cosmote.net - High
17 8.209.64.96 - - High
18 12.5.37.3 - - High
19 12.167.151.78 - - High
20 12.167.151.79 - - High
21 12.167.151.81 - - High
22 12.167.151.85 - - High
23 12.167.151.87 - - High
24 12.167.151.89 - - High
25 23.111.114.52 - - High
26 24.42.14.241 - - High
27 24.43.22.221 rrcs-24-43-22-221.west.biz.rr.com - High
28 24.55.67.176 dynamic.libertypr.net - High
29 24.55.112.61 dynamic.libertypr.net - High
30 24.90.160.91 cpe-24-90-160-91.nyc.res.rr.com - High
31 24.95.61.62 cpe-24-95-61-62.columbus.res.rr.com - High
32 24.110.14.40 - - High
33 24.110.96.149 - - High
34 24.117.107.120 24-117-107-120.cpe.sparklight.net - High
35 24.122.118.18 24-122-118-18.resi.cgocable.ca - High
36 24.139.72.117 - - High
37 24.139.132.70 dynamic.libertypr.net - High
38 24.152.219.253 24.152.219.253.res-cmts.sm.ptd.net - High
39 24.164.79.147 cpe-24-164-79-147.cinci.res.rr.com - High
40 24.165.87.61 cpe-24-165-87-61.san.res.rr.com - High
41 24.178.196.158 024-178-196-158.biz.spectrum.com - High
42 24.183.39.93 024-183-039-093.res.spectrum.com - High
43 24.202.42.48 modemcable048.42-202-24.mc.videotron.ca - High
44 24.226.156.153 24-226-156-153.resi.cgocable.ca - High
45 24.229.150.54 24.229.150.54.cmts-static.sm.ptd.net - High
46 24.234.86.201 wsip-24-234-86-201.lv.lv.cox.net - High
47 27.223.92.142 - - High
48 31.35.28.29 i15-les04-th2-31-35-28-29.sfr.lns.abo.bbox.fr - High
49 31.48.174.63 host31-48-174-63.range31-48.btcentralplus.com - High
50 32.221.224.140 - - High
51 35.142.12.163 035-142-012-163.dhcp.bhn.net - High
52 35.208.146.4 4.146.208.35.bc.googleusercontent.com - Medium
53 36.77.151.211 - - High
54 37.34.253.233 - - High
55 37.156.243.67 - - High
56 37.182.238.170 net-37-182-238-170.cust.vodafonedsl.it - High
57 37.186.54.254 - - High
58 38.70.253.226 38.70.253.226.sumofiber.net - High
59 39.36.61.58 - - High
60 39.41.29.200 - - High
61 39.44.158.215 - - High
62 39.44.213.68 - - High
63 39.49.96.122 - - High
64 39.52.41.80 - - High
65 40.134.246.185 h185.246.134.40.static.ip.windstream.net - High
66 41.34.91.90 host-41.34.91.90.tedata.net - High
67 41.38.167.179 host-41.38.167.179.tedata.net - High
68 41.84.229.240 - - High
69 41.86.42.158 - - High
70 41.97.138.74 - - High
71 41.215.153.104 - - High
72 41.225.231.43 - - High
73 41.228.22.180 - - High
74 41.228.206.99 - - High
75 41.230.62.211 - - High
76 42.228.224.249 hn.kd.ny.adsl - High
77 45.32.211.207 45.32.211.207.vultr.com - Medium
78 45.45.51.182 modemcable182.51-45-45.mc.videotron.ca - High
79 45.46.53.140 cpe-45-46-53-140.maine.res.rr.com - High
80 45.63.1.12 45.63.1.12.vultrusercontent.com - High
81 45.63.107.192 45.63.107.192.vultr.com - Medium
82 45.67.231.247 vm272927.pq.hosting - High
83 45.76.167.26 45.76.167.26.vultrusercontent.com - High
84 45.77.115.208 45.77.115.208.vultr.com - Medium
85 45.77.117.108 45.77.117.108.vultr.com - Medium
86 45.77.215.141 45.77.215.141.vultr.com - Medium
87 45.230.228.26 - - High
88 46.107.48.202 2E6B30CA.catv.pool.telekom.hu - High
89 46.214.62.199 46-214-62-199.next-gen.ro - High
90 46.228.199.235 vps2231940.fastwebserver.de - High
91 47.22.148.6 ool-2f169406.static.optonline.net - High
92 47.23.89.60 ool-2f17593c.static.optonline.net - High
93 47.24.47.218 047-024-047-218.res.spectrum.com - High
94 47.28.135.155 047-028-135-155.res.spectrum.com - High
95 47.44.217.98 047-044-217-098.biz.spectrum.com - High
96 47.138.200.85 - - High
97 47.153.115.154 - - High
98 47.156.131.10 47-156-131-10.lsan.ca.frontiernet.net - High
99 47.157.227.70 - - High
100 47.180.66.10 static-47-180-66-10.lsan.ca.frontiernet.net - High
101 47.196.192.184 - - High
102 49.144.81.46 dsl.49.144.81.46.pldt.net - High
103 49.191.4.245 n49-191-4-245.mrk1.qld.optusnet.com.au - High
104 49.207.105.25 broadband.actcorp.in - High
105 50.29.166.232 50.29.166.232.res-cmts.sth3.ptd.net - High
106 50.87.150.203 mail.euroanatolia.eu - High
107 50.91.114.38 050-091-114-038.res.spectrum.com - High
108 50.104.68.223 50-104-68-223.prtg.in.frontiernet.net - High
109 50.244.112.106 50-244-112-106-static.hfc.comcastbusiness.net - High
110 51.210.14.58 vps-e6e2a926.vps.ovh.net - High
111 52.45.143.178 ec2-52-45-143-178.compute-1.amazonaws.com - Medium
112 52.201.200.28 ec2-52-201-200-28.compute-1.amazonaws.com - Medium
113 54.36.108.120 ns3112762.ip-54-36-108.eu - High
114 58.233.220.182 - - High
115 59.90.246.200 static.bb.chn.59.90.246.200.bsnl.in - High
116 59.124.10.133 59-124-10-133.hinet-ip.hinet.net - High
117 62.38.114.12 ppp062038114012.dsl.hol.gr - High
118 62.121.123.57 - - High
119 63.143.92.99 - - High
120 64.19.74.29 primhall.com - High
121 64.29.151.102 mail.myfairpoint.net - High
122 64.34.169.244 srv1.1572.activeminds.net - High
123 ... ... ... ...

There are 488 more IOC items available. Please use our online service to access the data.

TTP - Tactics, Techniques, Procedures

Tactics, techniques, and procedures (TTP) summarize the suspected MITRE ATT&CK techniques used by Qakbot. This data is unique as it uses our predictive model for actor profiling.

ID Technique Weakness Description Confidence
1 T1059.007 CWE-79, CWE-80 Cross Site Scripting High
2 T1068 CWE-264, CWE-284 Execution with Unnecessary Privileges High
3 T1110.001 CWE-307 Improper Restriction of Excessive Authentication Attempts High
4 ... ... ... ...

There are 7 more TTP items available. Please use our online service to access the data.

IOA - Indicator of Attack

These indicators of attack (IOA) list the potential fragments used for technical activities like reconnaissance, exploitation, privilege escalation, and exfiltration by Qakbot. This data is unique as it uses our predictive model for actor profiling.

ID Type Indicator Confidence
1 File .htaccess Medium
2 File /#/CampaignManager/users High
3 File /admin/?setting-base.htm High
4 File /admin/admin_login.php High
5 File /admin/login.php High
6 File /bin/sh Low
7 File /componetns/user/class.user.php High
8 File /debug/pprof Medium
9 File /dev/tty Medium
10 File /doorgets/app/requests/user/modulecategoryRequest.php High
11 File /gaia-job-admin/user/add High
12 File /HNAP1 Low
13 File /include/chart_generator.php High
14 File /login Low
15 File /login.html Medium
16 File /magnoliaPublic/travel/members/login.html High
17 File /member/index/login.html High
18 File /requests.php High
19 File /rest/api/latest/projectvalidate/key High
20 File /saml/login Medium
21 File /ScadaBR/login.htm High
22 File /ServletAPI/accounts/login High
23 File /uncpath/ Medium
24 File /upload Low
25 File /var/adm/btmp High
26 File /var/log/messages High
27 File /websocket/exec High
28 File 14all.cgi/14all-1.1.cgi/traffic.cgi/mrtg.cgi High
29 File account/login.php High
30 File ad/login.asp Medium
31 File add.php Low
32 File admin.inc.php High
33 File admin.php Medium
34 File admin/admin_ping.php High
35 File admin/index.php High
36 File admin/login.asp High
37 File admin/login.php High
38 File admin/nos/login High
39 File admin/viewtheatre.php High
40 File adminer.php Medium
41 File admin_ajax.php?action=checkrepeat High
42 File admin_delete.php High
43 File agenda.php3 Medium
44 File ajaxp.php Medium
45 ... ... ...

There are 387 more IOA items available (file, library, argument, input value, pattern, network port). Please use our online service to access the data.

References

The following list contains external sources which discuss the actor and the associated activities:

Literature

The following articles explain our unique predictive cyber threat intelligence:

License

(c) 1997-2022 by vuldb.com. All data on this page is shared under the license CC BY-NC-SA 4.0. Questions? Check the FAQ, read the documentation or contact us!