{"id":777,"date":"2020-09-22T19:16:36","date_gmt":"2020-09-23T00:16:36","guid":{"rendered":"https:\/\/truxgoservers.com\/blog\/?p=777"},"modified":"2020-09-22T19:16:37","modified_gmt":"2020-09-23T00:16:37","slug":"qbot-one-of-the-most-dangerous-malware","status":"publish","type":"post","link":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/","title":{"rendered":"QBOT &#8211; One of the most dangerous malware"},"content":{"rendered":"\n<p>Qbot, an information stealing Trojan that has been around for 10 years, has resurfaced again with a new phishing-based infection technique that is capable of bypassing anti-spam defenses. Varonis Security Research discovered the new Qbot campaign in March. Investigators have positively identified 2,726 victims, based on an analysis of one of the attacker&#8217;s servers. However, they suspect that the actual number of victims is much higher.<\/p>\n\n\n\n<p>Qbot, also known as QakBot, is known for its polymorphic behavior and its worm-like tendencies, such as the ability to self-replicate via shared drives and removable media. On this occasion, QBot has spread through a phishing campaign targeting US corporations and also victims in Europe, Asia and South America.<\/p>\n\n\n\n<p>The delivery mechanism for this variant of Qbot is through phishing campaigns, where victims receive an email containing a link to what appears to be an online document. The email is intended to be an existing email thread, under the guise of responding to a pre-existing business correspondence, thus avoiding spam filters. The target of the attacks is to steal financial information, including bank account credentials.<\/p>\n\n\n\n<p>The infection technique is typical. A phishing email arrives with a link to a Microsoft OneDrive file that delivers an edition of Microsoft Visual Basic Scripts (VBScript) in a compressed ZIP file. If the file is opened, the attack spawns the legitimate Windows BITSAdmin utility. This activates another native Windows utility, Wscript.exe, which is used to download the Qbot malware file &#8220;august.png&#8221; from the attacker&#8217;s server.<\/p>\n\n\n\n<p>And it is that the French national cybersecurity agency has issued a notice about an increase in attacks in which Emotet is being used, targeting both the private sector and public entities. \u201cFor several days, ANSSI has observed that Emotet malware targets French companies and administrations,\u201d the alert issued by ANSSI indicates, Special attention should be paid because Emotet is now used to implement other malicious code that can have a strong impact in the activity of the victims. <\/p>\n\n\n\n<p>And why did we mention Emotet in this article based on Qbot? Well, because in the attacks detected by the French authorities, Emotet has been used to deliver various variants of this family of Qbot.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Qbot, an information stealing Trojan that has been around for 10 years, has resurfaced again with a new phishing-based infection technique that is capable of bypassing anti-spam defenses. Varonis Security Research discovered the new Qbot campaign in March. Investigators have positively identified 2,726 victims, based on an analysis of one of the attacker&#8217;s servers. However, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":779,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10,15],"tags":[143,105,106],"class_list":["post-777","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","category-virus","tag-cyberattacks","tag-ransomware","tag-trojan"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.5 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>QBOT - One of the most dangerous malware - Truxgo Server Blog<\/title>\n<meta name=\"description\" content=\"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/\" \/>\n<meta property=\"og:locale\" content=\"es_MX\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"QBOT - One of the most dangerous malware - Truxgo Server Blog\" \/>\n<meta property=\"og:description\" content=\"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/\" \/>\n<meta property=\"og:site_name\" content=\"Truxgo Server Blog\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-23T00:16:36+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-09-23T00:16:37+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"800\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Truxgo\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"Truxgo\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/\"},\"author\":{\"name\":\"Truxgo\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\"},\"headline\":\"QBOT &#8211; One of the most dangerous malware\",\"datePublished\":\"2020-09-23T00:16:36+00:00\",\"dateModified\":\"2020-09-23T00:16:37+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/\"},\"wordCount\":371,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/QBOT.jpg\",\"keywords\":[\"Cyberattacks\",\"Ransomware\",\"Trojan\"],\"articleSection\":[\"Cybersecurity\",\"Virus\"],\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/\",\"name\":\"QBOT - One of the most dangerous malware - Truxgo Server Blog\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/QBOT.jpg\",\"datePublished\":\"2020-09-23T00:16:36+00:00\",\"dateModified\":\"2020-09-23T00:16:37+00:00\",\"description\":\"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#primaryimage\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/QBOT.jpg\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/QBOT.jpg\",\"width\":1200,\"height\":800},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/qbot-one-of-the-most-dangerous-malware\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"QBOT &#8211; One of the most dangerous malware\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"name\":\"Truxgo Server Blog\",\"description\":\"Cloud Server and Hosting Tutorials.\",\"publisher\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#organization\",\"name\":\"Truxgo Server Blog\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"contentUrl\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/08\\\/cropped-truxgo-logo-blanco.png\",\"width\":1250,\"height\":278,\"caption\":\"Truxgo Server Blog\"},\"image\":{\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/#\\\/schema\\\/person\\\/8b409c26449db6aa09724b45331e333e\",\"name\":\"Truxgo\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g\",\"caption\":\"Truxgo\"},\"sameAs\":[\"https:\\\/\\\/truxgoservers.com\\\/blog\"],\"url\":\"https:\\\/\\\/truxgoservers.com\\\/blog\\\/author\\\/truxgo\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"QBOT - One of the most dangerous malware - Truxgo Server Blog","description":"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/","og_locale":"es_MX","og_type":"article","og_title":"QBOT - One of the most dangerous malware - Truxgo Server Blog","og_description":"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.","og_url":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/","og_site_name":"Truxgo Server Blog","article_published_time":"2020-09-23T00:16:36+00:00","article_modified_time":"2020-09-23T00:16:37+00:00","og_image":[{"width":1200,"height":800,"url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg","type":"image\/jpeg"}],"author":"Truxgo","twitter_card":"summary_large_image","twitter_misc":{"Escrito por":"Truxgo","Tiempo de lectura":"2 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#article","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/"},"author":{"name":"Truxgo","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e"},"headline":"QBOT &#8211; One of the most dangerous malware","datePublished":"2020-09-23T00:16:36+00:00","dateModified":"2020-09-23T00:16:37+00:00","mainEntityOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/"},"wordCount":371,"commentCount":0,"publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg","keywords":["Cyberattacks","Ransomware","Trojan"],"articleSection":["Cybersecurity","Virus"],"inLanguage":"es","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/","url":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/","name":"QBOT - One of the most dangerous malware - Truxgo Server Blog","isPartOf":{"@id":"https:\/\/truxgoservers.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#primaryimage"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#primaryimage"},"thumbnailUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg","datePublished":"2020-09-23T00:16:36+00:00","dateModified":"2020-09-23T00:16:37+00:00","description":"QBOT a Trojan that has been on the lookout for a long time returns and here we will see what it does and why it is one of the most dangerous.","breadcrumb":{"@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#primaryimage","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/09\/QBOT.jpg","width":1200,"height":800},{"@type":"BreadcrumbList","@id":"https:\/\/truxgoservers.com\/blog\/qbot-one-of-the-most-dangerous-malware\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/truxgoservers.com\/blog\/"},{"@type":"ListItem","position":2,"name":"QBOT &#8211; One of the most dangerous malware"}]},{"@type":"WebSite","@id":"https:\/\/truxgoservers.com\/blog\/#website","url":"https:\/\/truxgoservers.com\/blog\/","name":"Truxgo Server Blog","description":"Cloud Server and Hosting Tutorials.","publisher":{"@id":"https:\/\/truxgoservers.com\/blog\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/truxgoservers.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/truxgoservers.com\/blog\/#organization","name":"Truxgo Server Blog","url":"https:\/\/truxgoservers.com\/blog\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","contentUrl":"https:\/\/truxgoservers.com\/blog\/wp-content\/uploads\/2020\/08\/cropped-truxgo-logo-blanco.png","width":1250,"height":278,"caption":"Truxgo Server Blog"},"image":{"@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/truxgoservers.com\/blog\/#\/schema\/person\/8b409c26449db6aa09724b45331e333e","name":"Truxgo","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/52691a61c58e68677ed4860007c1bb03b14eabe7350747ab3fad3e17825b4b96?s=96&d=mm&r=g","caption":"Truxgo"},"sameAs":["https:\/\/truxgoservers.com\/blog"],"url":"https:\/\/truxgoservers.com\/blog\/author\/truxgo\/"}]}},"_links":{"self":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/777","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/comments?post=777"}],"version-history":[{"count":1,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/777\/revisions"}],"predecessor-version":[{"id":778,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/posts\/777\/revisions\/778"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media\/779"}],"wp:attachment":[{"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/media?parent=777"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/categories?post=777"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/truxgoservers.com\/blog\/wp-json\/wp\/v2\/tags?post=777"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}