<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Quantloader &#8211; ViriBack Blog</title>
	<atom:link href="https://viriback.com/tag/quantloader/feed/" rel="self" type="application/rss+xml" />
	<link>https://viriback.com</link>
	<description>Malware Tracker, IOCs &#38; more ...</description>
	<lastBuildDate>Sun, 10 Jun 2018 11:21:48 +0000</lastBuildDate>
	<language>en-CA</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>

<image>
	<url>https://viriback.com/wp-content/uploads/2019/01/cropped-android-chrome-512x512-32x32.png</url>
	<title>Quantloader &#8211; ViriBack Blog</title>
	<link>https://viriback.com</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>6 months of QuantLoader</title>
		<link>https://viriback.com/6-months-of-quantloader/</link>
		
		<dc:creator><![CDATA[Viriback]]></dc:creator>
		<pubDate>Sun, 10 Jun 2018 11:04:47 +0000</pubDate>
				<category><![CDATA[Malware]]></category>
		<category><![CDATA[Quantloader]]></category>
		<guid isPermaLink="false">https://viriback.com/?p=59</guid>

					<description><![CDATA[Last december 2017, I started to actively hunt for Malware c2 web panels via virustotal submissions and open source data. I encountered 37 families of malware that had an HTTP web panels. Some are very common, like lokibot, pony, some are old, like AthenaHTTP etc... While there is no novelty to this article, it is  [...]]]></description>
										<content:encoded><![CDATA[<p><img fetchpriority="high" decoding="async" class="alignright size-medium wp-image-61" src="https://viriback.com/wp-content/uploads/2018/06/quantloader-300x180.png" alt="" width="300" height="180" srcset="https://viriback.com/wp-content/uploads/2018/06/quantloader-300x180.png 300w, https://viriback.com/wp-content/uploads/2018/06/quantloader.png 493w" sizes="(max-width: 300px) 100vw, 300px" />Last december 2017, I started to actively hunt for Malware c2 web panels via virustotal submissions and open source data. I encountered 37 families of malware that had an HTTP web panels. Some are very common, like lokibot, pony, some are old, like AthenaHTTP etc&#8230;</p>
<p>While there is no novelty to this article, it is more a compilation of my observation on QuantLoader activities for the last 6 months approximatly and a collection of IOCs.</p>
<p>During that period I observed 25 different C2 web panels of QuantLoader. Some have been up not even for 24hrs while one has been up for almost half a year.</p>
<p>My methodology is simple, I look at submissions on virustotal after searching for specific queries. Searching for specififc queries permits to narrow down the submission to target families of malware. This is far from perfect as I could miss a few activities of certain family but seems to work relatively well.</p>
<p><img decoding="async" class="aligncenter size-large wp-image-74" src="https://viriback.com/wp-content/uploads/2018/06/graphquant2-1024x548.png" alt="" width="700" height="375" srcset="https://viriback.com/wp-content/uploads/2018/06/graphquant2-300x161.png 300w, https://viriback.com/wp-content/uploads/2018/06/graphquant2-768x411.png 768w, https://viriback.com/wp-content/uploads/2018/06/graphquant2-1024x548.png 1024w, https://viriback.com/wp-content/uploads/2018/06/graphquant2.png 1134w" sizes="(max-width: 700px) 100vw, 700px" /></p>
<p>Here is the list of observed panels with their first seen date, last seen date and numbers of days being up:</p>
<table class="table table-bordered table-hover table-condensed">
<tbody>
<tr>
<td>Panel_url</td>
<td>First_seen</td>
<td>Last_seen</td>
<td>Days</td>
</tr>
<tr>
<td>http://dackdack.online/api2/admin/</td>
<td>20171217</td>
<td>20180610</td>
<td>175</td>
</tr>
<tr>
<td>http://dnspod.pro/pro/admin/</td>
<td>20180220</td>
<td>20180610</td>
<td>110</td>
</tr>
<tr>
<td>http://apple-shop.tech/Gtf7xfRd3bnj/admin/</td>
<td>20171225</td>
<td>20180402</td>
<td>98</td>
</tr>
<tr>
<td>http://195.22.127.170/q/admin/</td>
<td>20180310</td>
<td>20180610</td>
<td>92</td>
</tr>
<tr>
<td>http://aleaha.info/q/admin/</td>
<td>20180309</td>
<td>20180529</td>
<td>81</td>
</tr>
<tr>
<td>http://data.michaelorth.eu/q/admin/</td>
<td>20180405</td>
<td>20180610</td>
<td>66</td>
</tr>
<tr>
<td>http://login.americapsolutions.com/q/admin/</td>
<td>20180409</td>
<td>20180610</td>
<td>62</td>
</tr>
<tr>
<td>http://mts2015stm.myjino.ru/q/admin/</td>
<td>20171217</td>
<td>20180126</td>
<td>40</td>
</tr>
<tr>
<td>http://dandiesinoz.com/scripts/backup/admin/</td>
<td>20171217</td>
<td>20180124</td>
<td>38</td>
</tr>
<tr>
<td>http://tytoldran.win/q/admin/</td>
<td>20180222</td>
<td>20180326</td>
<td>32</td>
</tr>
<tr>
<td>http://windowsreport.stream/q/admin/</td>
<td>20171217</td>
<td>20180115</td>
<td>29</td>
</tr>
<tr>
<td>http://rolwiluld.win/q/admin/</td>
<td>20180226</td>
<td>20180326</td>
<td>28</td>
</tr>
<tr>
<td>http://myyu.ru/q/admin/</td>
<td>20171217</td>
<td>20180110</td>
<td>24</td>
</tr>
<tr>
<td>http://heroskatopirango.com/391f4jda9s/a/admin/</td>
<td>20180518</td>
<td>20180610</td>
<td>23</td>
</tr>
<tr>
<td>http://myothow.com/q2/admin/</td>
<td>20180208</td>
<td>20180227</td>
<td>19</td>
</tr>
<tr>
<td>http://fortresmuch.com/q2/admin/</td>
<td>20180208</td>
<td>20180227</td>
<td>19</td>
</tr>
<tr>
<td>http://dada.grantflaskparty.com/admin/</td>
<td>20180514</td>
<td>20180527</td>
<td>13</td>
</tr>
<tr>
<td>http://rec-tube.date/carting/admin/</td>
<td>20180311</td>
<td>20180324</td>
<td>13</td>
</tr>
<tr>
<td>http://javelinkay.club/reader/admin/</td>
<td>20180331</td>
<td>20180410</td>
<td>10</td>
</tr>
<tr>
<td>http://serolotb.com/q/admin/</td>
<td>20171217</td>
<td>20171227</td>
<td>10</td>
</tr>
<tr>
<td>http://cynagotceter.in/q2/admin/</td>
<td>20180327</td>
<td>20180403</td>
<td>7</td>
</tr>
<tr>
<td>http://wassronledorhad.in/q2/admin/</td>
<td>20180307</td>
<td>20180313</td>
<td>6</td>
</tr>
<tr>
<td>http://warpje.xyz/quant/admin/</td>
<td>20180111</td>
<td>20180115</td>
<td>4</td>
</tr>
<tr>
<td>http://bima.website/admin/</td>
<td>20180318</td>
<td>20180320</td>
<td>2</td>
</tr>
<tr>
<td>http://newdawncheat.club/q/admin/</td>
<td>20180223</td>
<td>20180223</td>
<td>0</td>
</tr>
</tbody>
</table>
<p>Here is the dump of IOCs group by C2 panel urls:</p>
<blockquote><p>http://195.22.127.170/q/admin/<br />
195.22.127.170<br />
eae17082ded2153c4b9c7dc7ad7f6b7e</p></blockquote>
<blockquote><p>http://aleaha.info/q/admin/<br />
aleaha.info<br />
94.154.14.150<br />
a412294a2d5bc43e929d4be7f679b956<br />
35d727cf1e8dfc74d81043536f458840</p></blockquote>
<blockquote><p>http://apple-shop.tech/Gtf7xfRd3bnj/admin/<br />
apple-shop.tech<br />
37.1.201.91<br />
8b6f7b420072d95e8da65df7f4aa1b5d</p></blockquote>
<blockquote><p>http://bima.website/admin/<br />
bima.website<br />
185.241.55.242<br />
3a2534afc6e50555e18d34030a356f94</p></blockquote>
<blockquote><p>http://cynagotceter.in/q2/admin/<br />
cynagotceter.in<br />
49.51.230.174<br />
e6bbc52ff5f1ca8d5a705e16db96797d<br />
8bbffeabfce5932a31349333c3b13929<br />
1350d30aa6e02baa48af3411646d55e5</p></blockquote>
<blockquote><p>http://dackdack.online/api2/admin/<br />
dackdack.online<br />
104.168.140.87<br />
45.79.218.235<br />
206.189.77.19<br />
431c3a0f52955313121038dcc8b8f021<br />
ca9d18db1dfc3ad5a52402525ce0e52b<br />
04ce2ca848782de8278340787af03e6b<br />
e282e93caffd4affd50096bb4f009b31<br />
ceb24f0dfd5867c59c292cd6eef9d4dd</p></blockquote>
<blockquote><p>http://dada.grantflaskparty.com/admin/<br />
dada.grantflaskparty.com<br />
185.148.147.152<br />
bdb58831b33c3d3009490d16ff520386<br />
734d0a1cf0c233f1a30865c6c5a2d9b3<br />
3f7625566c2f3a35acfd7a14642e1bbd<br />
21cbba5bda95d96313881378d250f08e<br />
013f456bac4268047d917236a2ff262f<br />
e996e9b252991d87e6908bb3beddb393</p></blockquote>
<blockquote><p>http://dandiesinoz.com/scripts/backup/admin/<br />
dandiesinoz.com<br />
116.0.23.244<br />
a22c6aa5c0c470f2130720d0a1a4ad7c</p></blockquote>
<blockquote><p>http://data.michaelorth.eu/q/admin/<br />
data.michaelorth.eu<br />
194.58.119.193<br />
32ee820b1a32b23ad95cbff42790821a<br />
ac8de3d1d37e9cea76deb8bea8149f65<br />
c140241e3d820d7bd9a132c5f83e99bf<br />
10e8ea5b0391319f5a2794cd0f634624<br />
456c88705ef023d28327f7d1a86b81f3<br />
2eef86c9a85199249ecc5a867fd86390<br />
a384f4f75c88de6dd7f8533a5c400843<br />
9b29ab7418e2d09893b9c0c66760b554<br />
03175a6b6691964c2ed1bf123fb2d0ba<br />
4030b46d23eb1f00abb09d8c42f18a0c<br />
269870263ec4e37684da241752f4b5d7<br />
9bab405d34afa66fba19ec044dee3174<br />
8df4e1260345f6d54d1963b95820deda<br />
3316d264fa5a13cf6cf8ce6a71b0055d<br />
22502e23ca6970cb0571b56f69c37a65<br />
1e0ed91b51897400a4ca65b35f6ded5b<br />
913a742cf8f822e36702b728688aa692<br />
79536b1ecd2e4b91ac771553f74fefe1<br />
b663605f5ee5934f2adc45d768ac80ff<br />
1d84da6610ac43dc7112168fb406fb22<br />
1cc936f7c244ea822178b5a3c4ff3c7c<br />
90e31c2c541294836c227f8daa19125a<br />
58d3799f25096d766eda4f28066a93a9<br />
b41d1d1c60ca99c85906ca75a0ff3fa5<br />
10c02a83ac93a708b2c631b7fa5a559b<br />
1a22573774c891fc4f86a99f45dbc809<br />
64ff0ccf4a668c683ff3715116267c41<br />
467f40798700f10e8cbd9d482ad4dc9a<br />
b32803bfe5626409995a1300de76a700<br />
34a3e10080caefd4787334d2d438249b<br />
11912cd4ce45e06c1559802b66a77489<br />
58ef78d8b51caeb750ab10fd56197f79</p></blockquote>
<blockquote><p>http://dnspod.pro/pro/admin/<br />
dnspod.pro<br />
185.117.119.29<br />
588eace9102a9f67ef2a1f24322cc5b0</p></blockquote>
<blockquote><p>http://fortresmuch.com/q2/admin/<br />
fortresmuch.com<br />
119.28.111.49<br />
cf8165ddc1ce44835cb57ec226c08c4d<br />
07da5d3088a13d4db7d5300e84b11ca4</p></blockquote>
<blockquote><p>http://heroskatopirango.com/391f4jda9s/a/admin/<br />
heroskatopirango.com<br />
204.155.30.106<br />
0942974fbe31b4be3e12dd6d65f85478</p></blockquote>
<blockquote><p>http://javelinkay.club/reader/admin/<br />
javelinkay.club<br />
49.51.135.204<br />
6955ed0b43b3a5d33a1d9daf1f482923</p></blockquote>
<blockquote><p>http://login.americapsolutions.com/q/admin/<br />
login.americapsolutions.com<br />
194.58.119.193<br />
595eaef63066c95296fad6f0fe9ee41a</p></blockquote>
<blockquote><p>http://mts2015stm.myjino.ru/q/admin/<br />
mts2015stm.myjino.ru<br />
81.177.135.151<br />
88a0c0fcee3e8f46766dd25ce70c11b9<br />
47bb80b54e11d0ce1dc3179b46414cac</p></blockquote>
<blockquote><p>http://myyu.ru/q/admin/<br />
myyu.ru<br />
95.46.114.96<br />
a263ad4e55c797fa551ca9f9c576ff48<br />
ab87aa8d0818c6c9f99794f6c93f6d36</p></blockquote>
<blockquote><p>http://newdawncheat.club/q/admin/<br />
newdawncheat.club<br />
191.101.245.36<br />
0d0838e8c347d6f71c48bd3316cb0103</p></blockquote>
<blockquote><p>http://rec-tube.date/carting/admin/<br />
rec-tube.date<br />
191.101.245.46<br />
ce9c9edab5b8fc2905e90613a092a808</p></blockquote>
<blockquote><p>http://rolwiluld.win/q/admin/<br />
rolwiluld.win<br />
194.1.236.115<br />
dc3cb327730bd9ce48c6303bcb768b9c<br />
d54b25a98667215ae3958160f3ebd76d<br />
186b0653e11b870bdd173d8fa0d214ca<br />
e1468b0743822bed071274f0d2e7384f</p></blockquote>
<blockquote><p>http://serolotb.com/q/admin/<br />
serolotb.com<br />
185.117.75.92<br />
0370e27514bfd6282b5708b5b01b893d</p></blockquote>
<blockquote><p>http://tytoldran.win/q/admin/<br />
tytoldran.win<br />
194.1.236.115<br />
ed6f9b51cd3dd3d5cf2a9011c67b204b<br />
4fcab10c59be02cc0a50e2c280247ff0<br />
432b18e36bfd91dad68edfba581ef3ed<br />
0d1ce7055e828bbedd5be16e75841fed</p></blockquote>
<blockquote><p>http://warpje.xyz/quant/admin/<br />
warpje.xyz<br />
37.97.183.120<br />
438b06bfd279e7430d3a9a62246c93a6</p></blockquote>
<blockquote><p>http://wassronledorhad.in/q2/admin/<br />
wassronledorhad.in<br />
45.32.236.220<br />
e6e2025afee1679005a94438c924f58c</p></blockquote>
<blockquote><p>http://windowsreport.stream/q/admin/<br />
windowsreport.stream<br />
104.24.114.159<br />
c639b0b9ee0407051fc656a28f2b0e97<br />
98b94529813f27aafce8818b49288397<br />
54e6ab371b04161963c793796d90bc37</p></blockquote>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
