QakBot C2 Traffic

#QakBot #QBot #C2 #malware-traffic-analysis.net #ThreatFox #ec74a5c51106f0419184d0dd08fb05bc #fd4bc6cea4877646ccd62f0792ec0b62 #CapLoader #NetworkMiner

In this video I analyze network traffic from a QakBot (QBot) infection in order to identify the Command-and-Control (C2) traffic. The analyzed PCAP file is from malware-traffic-analysis.net. IOC ListC2 IP and port: 80.47.61.240:2222C2 IP and port: 185.80.53.210:443QakBot proxy IP and port: 23.111.11[...]

Read the full writeup in the blog post QakBot C2 Traffic