Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
57
Global rank
82 infographic chevron month
Month rank
78 infographic chevron week
Week rank
0
IOCs

Qbot is a banking Trojan — a malware designed to collect banking information from victims. Qbot targets organizations mostly in the US. It is equipped with various sophisticated evasion and info-stealing functions and worm-like functionality, and a strong persistence mechanism.

Botnet
Type
Unknown
Origin
1 January, 2009
First seen
10 August, 2026
Last seen
Also known as
Pinkslipbot
QakBot
Quakbot

How to analyze Qbot with ANY.RUN

Type
Unknown
Origin
1 January, 2009
First seen
10 August, 2026
Last seen

IOCs

IP addresses
2.16.204.161
48.209.138.168
48.209.6.48
48.209.138.189
48.192.1.64
104.18.33.89
23.11.40.157
34.111.175.102
2.21.110.208
2.23.246.9
34.104.35.123
2.18.64.27
167.172.140.235
2.16.204.90
108.138.26.95
199.232.210.172
142.251.127.102
23.216.77.10
23.219.139.90
142.251.14.100
Hashes
b183bd6414c5123465075d76d2413c999d569492fb543acbc29690b4b745bdf2
9edf54bbc75b4448e9191747ee85e76724f8db40cbf3c8948d1e726f13cf65e8
50aaf51a5c2d60e21e13238b31cbcc1f79b8fad80725d534bc7b6649ad807a39
81b2bd4ea98c8db66554fbc8d7637a1a69a130f331feb732b75caab4c4868fd5
b4d4dcd9594d372d7c0c975d80ef5802c88502895ed4b8a26ca62e225f2f18b0
93acdb79543d9248ca3fca661f3ac287e6004e4b3dafd79d4c4070794ffbf2ad
e0dadbc9cd1f1bd8ce3118cc3383e0d0f6d147f055265d498d99deea956ba00f
df3f619804a92fdb4057192dc43dd748ea778adc52bc498ce80524c014b81119
81994c69bcac3bb1212fb0ef5034b1d4f1b429265750022ac28a846bf13a6d89
a32e0a83001d2c5d41649063217923dac167809cab50ec5784078e41c9ec0f0f
641b843cb6ee7538ec267212694c9ef0616b9ac9ab14a0abd7cf020678d50b02
837def894a069786ff70e524b6b9cc16a7d745954c20f4623b6e6783150e5d37
ee06792197c3e025b84860a72460eaf628c66637685f8c52c5a08a9cc35d376c
56b96add1978b1abba286f7f8982b0efbe007d4a48b3ded6a4d408e01d753fe2
8dc562cda7217a3a52db898243de3e2ed68b80e62ddcb8619545ed0b4e7f65a8
a2db0201d36f07f3f99d1adf8b8eafb9cf9bb803d024fcc9327b77af56346861
1f3ffadd3b80c7f95be06e245410768e8302a24e573868da3c6fd91230025bdc
d95aed234f932a1c48a2b1b0d98c60ca31f962310c03158e2884ab4ddd3ea1e0
583500b76965eb54b03493372989ab4d3426f85462d1db232c5ae6706a4d6c58
ec6a56d981892bf251df1439bea425a5f6c7e1c7312d44bedd5e2957f270338c
Domains
www.bing.com
google.com
settings-win.data.microsoft.com
activation-v2.sls.microsoft.com
widget.trustpilot.com
img-s-msn-com.akamaized.net
oms.ccleaner.com
detectportal.firefox.com
assets.adobedtm.com
p13n.adobe.io
firefox.settings.services.mozilla.com
mozilla.map.fastly.net
c.go-mpulse.net
iecvlist.microsoft.com
cdn-production.ccleaner.com
ip-info.ff.avast.com
trial-eum-clientnsv4-s.akamaihd.net
edge.microsoft.com
javadl-esd-secure.oracle.com
api.msn.com
URLs
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?319c53972f875bc5
https://hl2rcv.adobe.com/headlights/getsonar.aspx
https://hl2rcv.adobe.com/headlights/getconfig/
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbsnxliz3fu1wb6n1%2fe6xwn1b0jxiqqudiwawgbh3zfez70pn6odhb7tzrccea5qk96l6uywbka0h%2bvkxzy%3d
https://hbrcv.adobe.com/headlights/uploadfile/
http://ncc.avast.com/ncc.txt
https://ip-info.ff.avast.com/v2/info
http://emupdate.avcdn.net/files/emupdate/pong.txt
http://ccleaner.tools.avcdn.net/tools/ccleaner/update/ccupdate073_mv.cab
https://javadl-esd-secure.oracle.com/update/1.8.0/map-m-1.8.0.xml
https://javadl-esd-secure.oracle.com/update/1.8.0/ba687cb3cbb24342adc8fdf890b993dc/au-descriptor-1.8.0_501-b08.xml
https://analytics.ff.avast.com/receive3
http://ocsp.pki.goog/gsr1/mfewtzbnmeswstajbgurdgmcgguabbs3v7w2naf4fimtjpdjkg6%2bmggqmqquyhtmgkunl8qjuc99bm00qp%2f8%2fuscehe9dwzbnvka6iepxpby0w0%3d
http://ocsp.usertrust.com/mfiwudbomewwsjajbgurdgmcgguabbtnmnjmndqcqx8fcbwk16ehdims6qquu3m%2fwqorss9ugohym8cd8ridzssceqdsf7vb3jweuhatyulyyjne
http://c.pki.goog/wr3/sew80agzmpq.crl
http://o.pki.goog/s/wr3/wbw/mfiwudbomewwsjajbgurdgmcgguabbqsq0i5t2pafi2gw9uzwnc7ktctwgqux4h1%2fy6i2qa8twoiudekom4j%2fimceqdahfdgzzhe5bj20tffil6c
http://o.pki.goog/s/wr3/63y/mfiwudbomewwsjajbgurdgmcgguabbqsq0i5t2pafi2gw9uzwnc7ktctwgqux4h1%2fy6i2qa8twoiudekom4j%2fimceqdrdld4une0bameru4mntls
http://ocsp.sectigo.com/mfewtzbnmeswstajbgurdgmcgguabbrtito5p2rxxvy%2ftcludpziu1dscwquvnnyzjx5khqweioeynmhqbwiiukcecwaphbpq93d%2fxkbmykk7xe%3d
https://shepherd.ff.avast.com/?p_lng=en&p_lid=en-us&p_ads=1&p_devrsrch=1&p_thrdprt=0&p_thrdtr=0&p_midex=97b7721c4994e2556ff6a439510f665df3233a637833016fda6b2d652a6fc9cd&p_hid=19ce970b-f6c0-4a09-bae4-274b971730e0&p_ubs=50&p_trs=0&p_alp=0&p_jar=0&p_cclic=&p_chcc=0&p_bld=&p_pro=90&p_vep=6&p_ves=14&p_vbd=10584&p_osv=6.1&p_gksw=1&p_chr=0&p_sbi=0&p_scbu=0&p_tos=0&p_bau=0&p_dvt=3&p_bsls=0&p_gis=0&p_fds=222054&p_dslo=1130&p_chlo=2106&p_lit=0&p_avt=cc-pro-trial&p_age=2107&p_tcy=0&p_pct=0&p_jct=0
https://ip-info.ff.avast.com/v1/info
Last Seen at

Recent blog posts

post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 326
comments 0
post image
Smile, You're on Camera. Part 2: Hiring Lazar...
watchers 14459
comments 0
post image
Safeguarding 200M Users: How ChongLuaDao Scal...
watchers 7510
comments 0

What is Qbot?

Qbot, also known as QakBot, Pinkslipbot, and Quakbot, is a banking trojan — malware designed to steal banking credentials, online banking session information, personal details of the victim, or any other banking data.

Although early versions of Qbot were spotted all the way back in 2009, its creators have maintained this trojan. Today, it continues to be active and features worm-like abilities to spread over networks, supports advanced web-injections techniques, and has a persistence mechanism that some researchers believe to be one of the best in its class. Additionally, the trojan has anti-VM, anti-debug and anti-sandbox functionally that makes research and analysis quite difficult.

Furthermore, Qbot is polymorphic, which means that it can change itself even after it is installed on an endpoint. The Trojan constantly modifies files, and the dropper that the newer version of Qbot continuously cycles through command and control servers.

The combination of these functions makes QakBot highly dangerous malware. Qbot has been used in several successful attacks on organizations and governmental structures and has infected tens of thousands of machines.

General description of QakBot malware

Qbot is dispatched in targeted attacks against businesses. With this trojan, the attackers go after bank accounts of organizations or private users who access their personal online banking cabinets from corporate networks by piggybacking into banking sessions of the victim.

The Trojan uses man-in-the-browser functionality to perform web injections, allowing it to alter what the victims see on the banking website when browsing from an infected machine. Interestingly, while most malware samples that use this technique contain the web injection code in their config file, Qbot can fetch the code from a controlled domain as it performs malicious activity.

Another trait that differentiates Qbot from other Trojans is its worm-like functionality. Qbot can copy itself using shared drives and spread over the network, spreading on its own or after receiving a command from the command and control server. Together with a highly developed persistence mechanism that uses registry runkeys and scheduled tasks, these traits make erasing Qbot from the infected network very difficult. The Trojan is designed to sustain itself despite system reboots and automatically launch itself when the system is turned on again.

This infamous persistence functionality has allegedly caused compromise of sensitive information in two government organizations in Massachusetts in 2011, while worm-like behavior helped the Qbot infiltrate thousands of machines and create a botnet with over 1,500 devices resulting from that attack.

Most of the targets that Qbot goes after are US-based organizations. Only about twenty percent of the new attack businesses are located outside of the United States. Although apart from the government offices, most of the attacks have been directed at banking, tech, and healthcare industries, there is no hard evidence to suggest that the attackers are aiming at specific fields. This means that businesses working in any industry can get hit by QakBot.

It is also important to note that an advanced cybergang operates the malware. Qbot attacks have been appearing on the radar of security researchers periodically, with phases of high activity and intervals when attacks would completely stop. This behavior is likely to avoid attracting too much attention from law enforcement and allows attackers to tweak and improve the malware during their time off.

The group behind Qbot is also notoriously known for pushing out new modified malware samples at astonishing rates. They repack and re-scramble the code daily, making malware identification by means of anti-virus software unreliable.

Unfortunately, people's identities behind Qbot are unknown, but it is widely believed that the cyber gang is based somewhere in Eastern Europe.

Qbot malware analysis

This video recorded in the ANY.RUN interactive malware hunting service shows the execution process of Qbot. You can also research other malware like Netwire and Predator the Thief.

qbot_process_graph

Figure 1: Displays the tree of processes created by the ANY.RUN interactive malware hunting service

QakBot execution process

Since Qbot is mostly targeted at the corporate sector, the main way of its penetration into infected systems is through a malicious document. In our example, maldoc starts several processes, including Powershell through by using a macro. Then, using cmd.exe, this trojan starts a chain of commands and executions, creating folders and temporary files. It utilizes Powershell to download the payload. Notably, the payload's name is as simple as six of the same digits or, less often, letters. Also, the payload often has a .png extension, although it is an executable file.

After that trojan starts its main execution, QakBot tries to evade detection by overwriting itself with the legitimate Windows executable calc.exe using the following commands: cmd.exe /c ping.exe -n 6 127.0.0.1 & type "C:\Windows\System32\calc.exe" > “Path to malware executable.” Qbot also injects explorer.exe and adds itself into autorun for persistence.

Qbot distribution

Qbot uses multiple attack vectors to infect victims. The malware uses email spam and phishing campaigns, as well as vulnerability exploits to infiltrate its targets. One of the more recent versions of the malware was observed being distributed by a dropper.

The dropper that installs Qbot is equipped with a delayed execution function. This means that after the dropper itself is downloaded onto a target machine, it waits around fifteen minutes before dropping the payload, likely in an effort to trick automatic sandboxes and avoid detection.

How to detect Qbot using ANY.RUN?

Sometimes Qbot trojan creates files that allow analysts to detect it with a high degree of certainty. To detect Qbot, open the "Files" tab in the lower part of the task's window and take a look at the created folders. If you see folders with names such as "Zulycjadyc" and "imtaykad" within C:\Users\admin\AppData\ Roaming\Microsoft\ directory and .exe or .dat file with a name "ytfovlym," as shown on the figure below, be sure that it is Qbot in front of you.

how_to_detect_qbot

Figure 2: Detecting Qbot by local files

Conclusion

Security researchers successfully reversed a sample of QakBot in a 2020 investigation. Since the researchers managed to pinpoint a command and control server, they could identify the true scale of the attack. What they uncovered was an active Qbot botnet consisting of over 2,000 computers.

If there was any doubt that Qbot is a severe threat, hopefully, this should clear it. Advanced web injections, sophisticated anti-evasion techniques, worm-like functions, and an experienced cyber gang that constantly updates the malware is a dangerous cocktail.

As security researchers, it is essential to analyze malware like Qbot since code obfuscation makes research complicated. Every investigation has the potential to uncover important data that will help businesses avoid attacks or identify and eradicate this Trojan quicker. At the same time, Qbot avoids dynamic analysis with some automatic sandboxes with the delayed execution of its dropper and other tricks, interactive sandboxes like the one presented by the ANY.RUN malware hunting services are not so easily fooled.

ANY.RUN presents a good opportunity to perform dynamic analysis on this malware from a secure online environment and share your findings with fellow researchers in our public malware database.

HAVE A LOOK AT

Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
BTMOB RAT screenshot
BTMOB RAT
btmob
BTMOB RAT is a remote access Trojan (RAT) designed to give attackers full control over infected devices. It targets Windows and Android endpoints. Its modular structure allows operators to tailor capabilities, making it suitable for espionage, credential theft, financial fraud, and establishing long-term footholds in corporate networks.
Read More
SSLoad screenshot
SSLoad
ssload
SSLoad is a malicious loader or downloader that is used to infiltrate target systems through phishing emails, perform reconnaissance and transmit it back to its operators delivering malicious payloads. To avoid detection, SSLoad employs various encryption methods and delivery techniques highlighting its versatile nature and complexity. It is believed to be a part of Malware-as-a-Service (MaaS) operation given its diverse delivery methods and implemented techniques.
Read More
Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More
Sneaky 2FA screenshot
Sneaky 2FA
sneaky2fa
Sneaky 2FA is an Adversary-in-the-Middle (AiTM) phishing kit targeting Microsoft 365 accounts. Distributed as a Phishing-as-a-Service (PhaaS) through a Telegram bot, this malware bypasses two-factor authentication (2FA) to steal credentials and session cookies, posing a significant threat to individuals and organizations.
Read More