2022-05-18 (WEDNESDAY) - TA578 THREAD-HIJACKED EMAILS AND ISO EXAMPLE FOR BUMBLEBEE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
NOTES:
- This is associated with more TA578 Bumblebee malware using thread-hijacked emails as a distribution vector.
- Backround on this activity can be found here.
ASSOCIATED FILES:
- 2022-05-18-TA578-malspam-4-examples.zip 8.4 kB (8,413 bytes)
- 2022-05-18-TA578-malspam-174634-UTC.eml (4,177 bytes)
- 2022-05-18-TA578-malspam-184425-UTC.eml (3,372 bytes)
- 2022-05-18-TA578-malspam-185413-UTC.eml (3,210 bytes)
- 2022-05-18-TA578-malspam-203709-UTC.eml (3,221 bytes)
- 2022-05-18-TA578-web-pages-for-ISO-file.zip 862 kB (862,841 bytes)
- 2022-05-18-TA578-step-1-storage.googleapis.com-urh21265vg2o9x.appspot.com-g-b-file-d-fZxgV38APHDew.html.txt (26,933 bytes)
- 2022-05-18-TA578-step-2-birobixt.com-img-logo.jpg.txt (861,136 bytes)
- 2022-05-18-TA578-downloaded-ISO-file-and-contents.zip 1.36 MB (1,357,638 bytes)
- document.iso (2,490,368 bytes)
- documents.lnk (1,612 bytes)
- textol.dll (999,424 bytes)
IMAGES
Shown above: Example of a TA578 thread-hijacked email for Bumblebee malware.
Shown above: Opening link from the email in a web browser returns an ISO file.
Shown above: Contents of downloaded ISO file.
Click here to return to the main page.