Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
Alerts on execution of the QbotUninstall.exe uninstaller when it matches known Qakbot uninstaller hashes.
- Product
- windows
- Category
- process_creation
- Author
- Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2023-08-31
- Updated
- 2026-07-31
What it detects
This rule flags Windows process executions where the image filename ends with \QbotUninstall.exe and/or matches specific file hashes associated with that uninstaller. Such activity matters because malware operators may remove or disrupt components after infection or during operational changes, and these uninstaller executions can indicate adversary follow-on actions. The detection relies on process creation telemetry, including the process image path/name and hash values (imphash and SHA256).
Reporting behind it
- justice.govhttps://www.justice.gov/usao-cdca/divisions/national-security-division/qakbot-resources
- virustotal.comhttps://www.virustotal.com/gui/file/7cdee5a583eacf24b1f142413aabb4e556ccf4ef3a4764ad084c1526cc90e117/community
- virustotal.comhttps://www.virustotal.com/gui/file/fab408536aa37c4abc8be97ab9c1f86cb33b63923d423fdc2859eb9d63fa8ea0/community
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Malware/Qakbot/proc_creation_win_malware_qakbot_uninstaller_cleanup.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Qakbot Uninstaller Execution via QbotUninstall.exe (Windows Process Creation)
id: 6e45d7f2-b50d-49ab-b5f4-31f043772ae6
status: test
description: This rule flags Windows process executions where the image filename ends with \QbotUninstall.exe and/or matches specific file hashes associated with that uninstaller. Such activity matters because malware operators may remove or disrupt components after infection or during operational changes, and these uninstaller executions can indicate adversary follow-on actions. The detection relies on process creation telemetry, including the process image path/name and hash values (imphash and SHA256).
references:
- https://www.justice.gov/usao-cdca/divisions/national-security-division/qakbot-resources
- https://www.virustotal.com/gui/file/7cdee5a583eacf24b1f142413aabb4e556ccf4ef3a4764ad084c1526cc90e117/community
- https://www.virustotal.com/gui/file/fab408536aa37c4abc8be97ab9c1f86cb33b63923d423fdc2859eb9d63fa8ea0/community
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2023/Malware/Qakbot/proc_creation_win_malware_qakbot_uninstaller_cleanup.yml
author: Florian Roth (Nextron Systems), Huntrule Team
date: 2023-08-31
modified: 2023-09-01
tags:
- attack.execution
- detection.emerging-threats
logsource:
category: process_creation
product: windows
detection:
selection:
- Image|endswith: \QbotUninstall.exe
- Hashes|contains:
- IMPHASH=E772C815072311D6FB8C3390743E6BE5
- SHA256=423A9D13D410E2DC38EABB9FDF3121D2072472D0426260283A638B822DCD5180
- SHA256=559CAE635F0D870652B9482EF436B31D4BB1A5A0F51750836F328D749291D0B6
- SHA256=855EB5481F77DDE5AD8FA6E9D953D4AEBC280DDDF9461144B16ED62817CC5071
- SHA256=FAB408536AA37C4ABC8BE97AB9C1F86CB33B63923D423FDC2859EB9D63FA8EA0
condition: selection
falsepositives:
- Unlikely
level: high
license: DRL-1.1
related:
- id: bc309b7a-3c29-4937-a4a3-e232473f9168
type: derived