Threat intelligence, Threat Research

SweetOrange ExploitKit and Qakbot (July 11, 2014)

by Security News

The Dell SonicWALL Threats Research Team has recently encountered an example of the Qakbot malware family. This long lived malware family was seen being dropped by a SweetOrange Exploit Kit. This bot has many features and capabilities and is a danger to sensitive networks and data.

Infection Cycle

This sample of Qakbot is self contained and, besides log and config files, only drops identical copies of itself to disk. Multiple stages of unpacking are required to reveal the full capabilities of the sample. After the initial execution, the original file is deleted with a typical invocation of cmd.exe:

Once the original file is melted via cmd.exe and the malware is unpacked in memory, it injects into numerous processes, particularly applications that stay resident in the system tray.

In this case, the main injection target was Skype process that was then used to beacon out to a command and control server.

This C&C traffic is very simple and serves as a beacon to let the attackers know that a new machine has been infected. The IP address of the infected machine and the malware-generated host identifier are the primary contents.

In addition to the beacon traffic, this malware also sends a record of the user's browsing behavior in real time.

The data is only URL-escaped and can be easily decoded to show the true nature of the HTTP traffic:

Indicators of Compromise

In order to persist upon reboot, the malware creates multiple run keys. Our analysis included one that uses the malware's "/c" flag to execute and inject a target application.

The following randomized mutexes were seen during analysis and are used to prevent unnecessary reinfection and to manage the different infection threads.

  • Sessions1BaseNamedObjectsfilea
  • Sessions1BaseNamedObjectsizbtitjv
  • Sessions1BaseNamedObjectskyeuyya
  • BaseNamedObjectskyeuyy
  • BaseNamedObjectstlkpito
  • BaseNamedObjectsdiges
  • BaseNamedObjectsfrxikyn

Summary

Overall, the purpose of this malware is to gain control of and gather information from the target machine. Qakbot has a variety of functionality and will steal banking information and other personal data and credentials. Dell SonicWall Gateway Anti-Virus provides protection against this threat with the following signature:

  • GAV: Qbot.BH

Share This Article

An Article By

Security News

The SonicWall Capture Labs Threat Research Team gathers, analyzes and vets cross-vector threat information from the SonicWall Capture Threat network, consisting of global devices and resources, including more than 1 million security sensors in nearly 200 countries and territories. The research team identifies, analyzes, and mitigates critical vulnerabilities and malware daily through in-depth research, which drives protection for all SonicWall customers. In addition to safeguarding networks globally, the research team supports the larger threat intelligence community by releasing weekly deep technical analyses of the most critical threats to small businesses, providing critical knowledge that defenders need to protect their networks.

Related Articles

  • Microsoft Security Bulletin Coverage for September 2026
    Read More
  • Oracle HTTP & WebLogic Servers Proxy Plug-in Authentication Bypass
    Read More
  • Global Threat Data, Worldwide Coverage: The 2023 SonicWall Cyber Threat Report
    Read More