MALWARE-FILE-TRANSFER Trojan.Win32.Qakbot -3

Rule ID

1232643

Severity

High

Description

QakBot is a modular banking trojan that has been used primarily by financially-motivated actors since at least 2007. QakBot is continuously maintained and developed and has evolved from an information stealer into a delivery agent for ransomware.

Impact

Information disclosure

Recommendation

Update vendor's patch.

IPS Category

Malware traffic

IPS Anomaly Group

N/A

IPS Rule Default Action

Deny

References

T1140

T1074.001

T1105

T1106

T1027

T1055

T1218.011

T1497

Keywords

N/A

Date Created

2023/04/28

Last Updated

2023/04/28

This website uses cookies to ensure you get the best experience on our website.

Learn more