Feb. 17, 2023, 2 p.m. | Dr Josh Stroschein

Dr Josh Stroschein www.youtube.com

As OneNote documents continue to plague organizations, I decided to take a look at yet another document, this one leads to a qbot (quakbot) infection. In this video, we'll use ProcMon and Process Hacker 2 to learn more about the process activity around OneNote documents. We'll then use Onedump to extract the script and decode it. Finally, we'll talk briefly about the DLL that is downloaded that leads to the qbot infection.

Sample SHA256: ec674e92a9d108d67d2cc0f1f2d20579a8ca8ba6e32af1fe0ed8a1067a426586

00:00 Introduction
00:52 Setting up …

continue dll document documents extract hacker infection learn malware onenote organizations process procmon qbot quakbot script trends video

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC