Ares Banking Trojan adds the old Qakbot DGA
ID: 90863143-4d20-5526-8c8e-416539d3bf79
STIX ID: report--90863143-4d20-5526-8c8e-416539d3bf79
Feed Name: Zscaler Security Research Blog
Zscaler ThreatLabz reports that the Ares banking trojan received August 2022 updates adding a fallback domain generation algorithm (DGA) functionally mirroring the defunct Qakbot DGA, using the NIST daytime protocol to derive the date and producing 150 candidate C2 domains per month; the report details code similarities and differences, a modified CRC64-based API hashing routine, a BBVA Mexico web-inject configuration, sample generated domains, SHA256 IOCs and a hardcoded C2 URL, and concludes the DGA increases Ares' resilience and potential for follow-on monetization attacks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
