EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

Identification and Disruption of QakBot Infrastructure

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Identification and Disruption of QakBot Infrastructure. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory Identification and Disruption of QakBot Infrastructure Release Date August 30, 2023 Alert Code AA23-242A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response SUMMARY The Cybersecurity and Infrastructure Security Agency (CISA) and Federal Bureau of Investigation (FBI) are releasing this joint Cybersecurity Advisory (CSA) to disseminate QakBot infrastructure indicators of compromise (IOCs) identified through FBI investigations as of August 2023. On August 25, FBI and international partners executed a coordinated operation to disrupt QakBot infrastructure worldwide. Disruption operations targeting QakBot infrastructure resulted in the botnet takeover, which severed the connection between victim computers and QakBot command and control (C2) servers. The FBI is working closely with industry partners to share information about the malware to maximize detection, remediation, and prevention measures for network defenders. CISA and FBI encourage organizations to implement the recommendations in the Mitigations section to reduce the likelihood of QakBot-related activity and promote identification of QakBot-facilitated ransomware and malware infections. Note: The disruption of QakBot infrastructure does not mitigate other previously installed malware or ransomware on victim computers. If potential compromise is detected, administrators should apply the incident response recommendations included in this CSA and report key findings to a local FBI Field Office or CISA at cisa.gov/report . Download the PDF version of this report: AA23-242A Identification and Disruption of QakBot Infrastructure (PDF, 570.50 KB ) For a downloadable copy of IOCs, see: AA23-242A STIX XML (XML, 51.62 KB ) AA23-242A STIX JSON (JSON, 43.12 KB ) TECHNICAL DETAI

Indicatori CISA verificabili

41 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T09:03:05.533317+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
ipv4-addr193[.]29[.]187[.]41
ipv4-addr188[.]127[.]243[.]193
ipv4-addr188[.]127[.]243[.]147
ipv4-addr188[.]127[.]243[.]145
ipv4-addr185[.]81[.]114[.]188
ipv4-addr95[.]211[.]250[.]117
ipv4-addr95[.]211[.]250[.]98
ipv4-addr95[.]211[.]250[.]97
ipv4-addr95[.]211[.]198[.]177
ipv4-addr95[.]211[.]172[.]109
ipv4-addr95[.]211[.]172[.]108
ipv4-addr95[.]211[.]172[.]86
ipv4-addr95[.]211[.]172[.]7
ipv4-addr95[.]211[.]172[.]6
ipv4-addr95[.]211[.]95[.]14
ipv4-addr94[.]198[.]53[.]17
ipv4-addr45[.]84[.]224[.]23
ipv4-addr23[.]236[.]181[.]102
ipv4-addr188[.]127[.]243[.]148
ipv4-addr51[.]195[.]49[.]228
ipv4-addr51[.]161[.]202[.]232
ipv4-addr190[.]2[.]143[.]38
ipv4-addr188[.]127[.]242[.]178
ipv4-addr188[.]127[.]242[.]119
ipv4-addr94[.]198[.]51[.]202
ipv4-addr188[.]127[.]243[.]133
ipv4-addr188[.]127[.]243[.]130
ipv4-addr94[.]198[.]50[.]210
ipv4-addr94[.]198[.]50[.]147
ipv4-addr193[.]201[.]9[.]93
ipv4-addr89[.]163[.]212[.]111
ipv4-addr87[.]117[.]247[.]41
ipv4-addr62[.]141[.]42[.]36
ipv4-addr185[.]4[.]67[.]6
ipv4-addr51[.]38[.]62[.]182
ipv4-addr51[.]38[.]62[.]181
ipv4-addr85[.]14[.]243[.]111
ipv4-addr46[.]151[.]30[.]109
ipv4-addr94[.]103[.]85[.]86
ipv4-addr188[.]241[.]58[.]140
ipv4-addr193[.]29[.]187[.]57

Provenance

Allegato ufficiale CISA · 2023-08-26T15:47:52Z

SHA-512: e75231106a75902e07cc32507ff11c2cec8ad1407ca1862f8cba4f9d9c0ed4b961547f5a1c5240fbd4e2eb1dad6e2cfc746e33f02238ac9c07fa20dea30b9bc8

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
30/08/2023 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1486, T1555.005, T1566.001
Classification
Critical
Stated country
US

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source