Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)

Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.

FreeReviewedSigma · High · v5
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-08-31
Updated
2026-07-31

What it detects

This rule flags Windows process executions where the image filename ends with \QbotUninstall.exe and/or matches specific file hashes associated with that uninstaller. Such activity matters because malware operators may remove or disrupt components after infection or during operational changes, and these uninstaller executions can indicate adversary follow-on actions. The detection relies on process creation telemetry, including the process image path/name and hash values (imphash and SHA256).

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.