New #Qealler CnC 192.254.79[.]67:80
Samples first showed-up on April 15th. Malicious #CnC server hosted on @CentriLogic
https://t.co/6w82edo3w4 ๐
๐๏ธ report: https://t.co/I6Kh8hzX4R
Shout-out to @Crose_96 and @malwrhunterteam for bringing my attention to it ๐
Overall: nothing seems to be new for these #Qealler samples (you know, other than the ๐ #CnC on @CentriLogic)
As @Crose_96 pointed out, #VT detection ratios are rather low - but that's normal โน๏ธ
(on average, the ratios are actually a bit higher than when I first started ๐น)
@Crose_96@malwrhunterteam@wwp96 The detection ratios are usually below 10 (originally)
Do you have the hash? Iโd love to take a look sometime tonight and see if thereโs anything significantly different
@Crose_96@malwrhunterteam@wwp96 Feel free DM me any time ๐ค
Also been working on a write-up analyzing #Qealler - but college courses really slowing me down tho
You can view some preliminary notes/artifacts here: https://t.co/kPtsPWSOVU
New #Qealler server for the blocklist ๐ฅ: 79.143.87[.]120:80
(first new one since 3/22)
https://t.co/bpWMcazkzk ๐
Qealler devs finally moved from Private Layer, this #CnC is hosted on #HyrdaCom
๐๏ธ sandbox: https://t.co/7bjSG7kfYr
Active #Qealler samples:๐ฌ
4b804f4defa52df0534b9acc5503b808 - https://t.co/O0RMtCcU7h
7312c90ad802c82304d349e671ba451c - https://t.co/OU1eI6AU6f
a9c77d8c90730be4c19acd41ee1963cf - https://t.co/UmhpLdhT2P
(improved detection ratios in #VT since I first started reporting ๐)
๐#Qealler server: 31.7.61[.]14:80
https://t.co/Mu2FMeD66d
Discovered by @wwp96 ๐ค
The Qealler devs seem to have settled on hosting #CnC servers at @PrivateLayer this season (see https://t.co/mEzKDdpDqs)
๐พSample: 426ce0823c081d2f4b9c491d9c302e77
https://t.co/MEgjPaPPxj [6/61]
Had to crawl through ~13000 lines of _horribly_ written #Java code, but I've finally managed to fully #ReverseEngineer the #Qealler payload ๐ฉโ๐ฌ
The #packer was way simpler than I thought - it was just like 200x larger than it needed to be ๐คฎ
https://t.co/2kvUzgZpa7
๐ #Qealler sample (yay?)
31.7.61[.]2:80 is the new #CnC server and my new target๐ฏ
https://t.co/TJzd4cjf8J
The server is once again hosted at @PrivateLayer (check your inbox, I have seen this pattern before)
๐๏ธSandbox report: https://t.co/rmLoGGypQ3
https://t.co/h4gNWvhTBT
3/58 detection ratio on #VT
Can't find payload URL (in class rn, will look later). Should be somewhere on fmjplastering[.]co[.]uk
Spent better part of the last week fully #reversing the 508a10013321a191f9699f24b542b04a sample๐ฉโ๐ฌ - hopefully done soon๐ค
One emailed PCAP later and #Qealler's new #CnC server is down. Big thanks to @PrivateLayer's Abuse Team๐
recent sandbox report: https://t.co/Sy2Z9zqLV7
โ Confirmed via dynamic analysis (see screenshot)
NOTHING makes me happier than watching malware get lost on its way home ๐
#Qealler is back ๐
The #CnC server at 179.43.145[.]245 - currently hosted at @PrivateLayer
https://t.co/q1TxzX9mn2
New sample (discovered by @wwp96) appears to be an updated instance of the #infostealer - at first glance the code is slightly more sophisticated
[1/2]