Exploit:JS/Blacole.Q
TrojanDropper:JS/Xibow.C
Windows Defender detects and removes this threat.
This trojan can install other malware or unwanted software onto your PC.
It can be installed when you open a spam email attachment.
Exploit:HTML/IframeRef.BG
Exploit:HTML/IframeRef.BG is a detection for an obfuscated exploit that is embedded within a compromised web page. The exploit creates a malicious IFrame into same web page that, when viewed in a web browser, redirects the browser to another site to possibly execute other malicious code.
Behavior:Win32/QbotScript
Microsoft Defender Antivirus detects and removes this threat.
Qakbot, also known as Quakbot, Qbot, and similar names, has been active since 2007. Qakbot started life as a credential stealer optimized to obtain credentials from banking and other financial services. In 2020 and 2021, Qakbot has been observed to lead to ransomware-as-a-service (RaaS) actors responsible for expedient ransomware and data exfiltration from organizations via purchased access to Qakbot infections.
Qakbot global campaign has been impacting organizations with malicious email deliveries that lead to infection with a renovated Qakbot implant that quickly ascertains system information to determine which organizations are valuable for resale. Qakbot transitions to human re-entry by a motivated operator based on the company or network profile obtained during reconnaissance. The consequences are likely to involve ransomware and data exfiltration as well as increased scope of organizational compromise.
Read these blogs for details: