In this video we analyze the Qakbot Malware Dropper. The file that starts the infection is an HTML File, the flow is as follows:
html drops .zip via html smuggling.
zip contains iso file.
iso contains .lnk.
Lnk file launches calc.exe,
calc.exe sideloads windowscodecs.dll
windowscodecs.dll executes the malicious payload dll (102755.dll).
Malware Sample: hxxps[://]bazaar[.]abuse[.]ch/sample/f5c16248418a4f1fd8dff438b26b8da7f587b77db9e180a82493bae140893687/
Malware Analysis Course Link: https://courses.null-char.com/courses...
Academy Link: https://ask-academy.live/
Please provide feedback in the comments.
To continue the conversation hit me up on twitter:
🐦 Twitter - / nu11charb
#malware #Qakbot #HTMLSmuggling #DLLSideLoading #reverseengineering