2021-08-12 (THURSDAY) - STOLEN IMAGES EVIDENCE.ZIP -> BAZARLOADER -> COBALT STRIKE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2021-08-12-BazarLoader-and-Cobalt-Strike-IOCs.txt.zip 1.3 kB (1,251 bytes)
- 2021-08-12-BazarLoader-and-Cobalt-Strike-IOCs.txt (1,784 bytes)
- 2021-08-12-BazarLoader-with-Cobalt-Strike.pcap.zip 12.7 MB (12,724,771 bytes)
- 2021-08-12-BazarLoader-with-Cobalt-Strike.pcap (14,639,797 bytes)
- 2021-08-12-malware-from-BazarLoader-infection.zip 115 kB (115,388 bytes)
- Stolen Images Evidence.js (23,004 bytes)
- Stolen Images Evidence.zip (7,831 bytes)
- VieFT.dat (190,984 bytes)
IMAGES
Shown above: Website that delivered Stolen Image Evidence.zip.
Shown above: Traffic from the infection filtered in Wireshark (part 1 of 2).
Shown above: Traffic from the infection filtered in Wireshark (part 2 of 2).
Click here to return to the main page.