General

  • Target

    c412873533f1978bb4ae8f7a1e2fc364

  • Size

    956KB

  • Sample

    240312-w9jhwsac83

  • MD5

    c412873533f1978bb4ae8f7a1e2fc364

  • SHA1

    ce2178d4cc6cd0942393084095afb700b2b66c95

  • SHA256

    3046cb75e9053a061c37009415b4b3313d605210f51bc48fe2621498264dbcd0

  • SHA512

    f6b88d8ca6b8de8b07a0deacce6179496377af324eac39c10f9e6a7ad58a79d0cda6437976993f591d35e28cb0efd0774aad6881b6763fb53e3615ffe7ef5152

  • SSDEEP

    12288:cgjcpLmq2lWk8gIFjJyslu0JULFwqrBEtyJIkGkL1QBNeUxLW40T2eF:HjSGl1IFFJ00SBwqV914NroT2c

Malware Config

Extracted

Family

bazarloader

C2

134.209.196.117

142.93.135.196

whitestorm9p.bazar

Targets

    • Target

      c412873533f1978bb4ae8f7a1e2fc364

    • Size

      956KB

    • MD5

      c412873533f1978bb4ae8f7a1e2fc364

    • SHA1

      ce2178d4cc6cd0942393084095afb700b2b66c95

    • SHA256

      3046cb75e9053a061c37009415b4b3313d605210f51bc48fe2621498264dbcd0

    • SHA512

      f6b88d8ca6b8de8b07a0deacce6179496377af324eac39c10f9e6a7ad58a79d0cda6437976993f591d35e28cb0efd0774aad6881b6763fb53e3615ffe7ef5152

    • SSDEEP

      12288:cgjcpLmq2lWk8gIFjJyslu0JULFwqrBEtyJIkGkL1QBNeUxLW40T2eF:HjSGl1IFFJ00SBwqV914NroT2c

    • Bazar Loader

      Detected loader normally used to deploy BazarBackdoor malware.

    • Bazar/Team9 Loader payload

MITRE ATT&CK Matrix

Tasks