IOCs

Indicators for QakBot

5 indicators · scoped to malware families · back to QakBot
Live IOCs from URLhaus, ThreatFox, MalwareBazaar, and abuse.ch SSLBL for malware families this tool uses. All indicators are defanged for safe handling.

Indicators

5 of 5
ip:port
27[.]133[.]154[.]218:443
family QakBot source feodo first seen 2026-03-04 14:28:39
ip:port
178[.]62[.]3[.]223:443
family QakBot source feodo first seen 2026-02-17 05:41:23
ip:port
34[.]204[.]119[.]63:443
family QakBot source feodo first seen 2026-01-13 21:41:15
ip:port
50[.]16[.]16[.]211:443
family QakBot source feodo first seen 2025-12-30 13:56:31
url
hxxp://xn--b1afiqif6c.xn--p1ai/mmjbbs/673484/NQAD_673484_01062020.zip
family Qakbot source urlhaus first seen 2020-06-02 08:23:36 UTC
Showing 1-5 of 5
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin