Qakbot Dropper Analysis

Опубликовано: 24 Апрель 2026
на канале: AhmedS Kasmani
4,764
111

In this video we analyze the Qakbot Malware Dropper. The file that starts the infection is an HTML File, the flow is as follows:

html drops .zip via html smuggling.
zip contains iso file.
iso contains .lnk.
Lnk file launches calc.exe,
calc.exe sideloads windowscodecs.dll
windowscodecs.dll executes the malicious payload dll (102755.dll).

Malware Sample: hxxps[://]bazaar[.]abuse[.]ch/sample/f5c16248418a4f1fd8dff438b26b8da7f587b77db9e180a82493bae140893687/

Malware Analysis Course Link: https://courses.null-char.com/courses...

Academy Link: https://ask-academy.live/

Please provide feedback in the comments.

To continue the conversation hit me up on twitter:

🐦 Twitter -   / nu11charb  

#malware #Qakbot #HTMLSmuggling #DLLSideLoading #reverseengineering