Top Tweets for #bazarloader
[QuickNote] Analysis of malware suspected to be an #APT attack targeting #Vietnam: https://t.co/IIqJBRRlns
[QuickNote] Techniques for decrypting #BazarLoader strings: https://t.co/fD2Vpr0Aqd
[QuickNote] Analysis of #Pandora ransomware: https://t.co/MIDhISafG9
(2/6)
@reecdeep @malwrhunterteam @executemalware @JAMESWT_MHT @James_inthe_box @guelfoweb @Tac_Mangusta @0xToxin @Max_Mal_ @VirITeXplorer This reminds me of #Bazarloader just without the use of .hta. They did similar staging techniques to download the final payload.
Two of these servers were detected in malicious activity earlier.
195.123.240[.]219 was mentioned in CISA's report from 2020 "Ransomware Activity Targeting the Healthcare and Public Health Sector", in connection with #BazarLoader and #Ryuk: https://t.co/lkmc0WiYrn
#Bumblebee #BazarLoader #CobaltStrike
C&C: 45.66.151[.]142
45.153.243[.]126
146.59.116[.]4
MD5:e6a046d1baa7cd2100bdf48102b8a144
d2bc7c2e9343e3f8313d643973fc1a56
d6a09a35b18a25b756fd0a2cfe18ecf1
see more IoC details on threatbook[.]io
![ThreatBookLabs's tweet photo. #Bumblebee #BazarLoader #CobaltStrike
C&C: 45.66.151[.]142
45.153.243[.]126
146.59.116[.]4
MD5:e6a046d1baa7cd2100bdf48102b8a144
d2bc7c2e9343e3f8313d643973fc1a56
d6a09a35b18a25b756fd0a2cfe18ecf1
see more IoC details on threatbook[.]io https://t.co/LhuJIStAc0](https://pbs.twimg.com/media/FhwvUINVEAAKXd2.png)
Эксперты Trellix: кампания BazarCall использует новую тактику обмана
#BazarCall, #BazarLoader, #Ruyk, #Trellix
https://t.co/s2WTMUz18c

There's a newly developed malware loader dubbed Bumblebee. More info on this new threat in the article linked below.
#bumblebee #trickbot #contisyndicate #bazarloader #icedid
https://t.co/UKxSrO7BvK
Hackers Deploy Bumblebee Loader to Breach Target Networks https://t.co/xYaIZKhkpr via @InfosecurityMag #bumblebeeloader #hackers #cybercrime #cyberthreat #bazarloader #trickbot #icedID #malware #LNKfiles #cybersecurity
#Hackers associated with #BazarLoader, #TrickBot, and #IcedID are increasingly using the #Bumblebee #malware loader in their campaigns to breach target networks for post-exploitation activities. #CyberAttack #CyberSecurity
Read: https://t.co/Mob8P7vUT9
The operators of the #BazarLoader #malware are working together with underground call centers to trick victims of their #spam campaigns into opening malicious #Office documents and infecting themselves with malware.1/2
https://t.co/kIF8vLBvPB
#BazarLoader uses a simple but effective obfuscation routine within its initial .hta loader. Here's how to decode it using a single #cyberchef recipe.
1/

#BazarLoader と #Zloader のサンプルにサンドボックス回避技術の1つ「APIハンマリング」を非常に特徴的に実装をしたものが見つかりました。見つかった手法、実装方法、保護対策を詳述します。https://t.co/27Ik5zoQtB

A major event marking the infostealer threat landscape was the end of #TrickBot’s operations in February. While it seemed that TrickBot’s creators would switch to the more sophisticated #BazarLoader, their focus appears to have shifted to a loader named #Bumblebee. 3/4

#Bumblebee, a new offering from the development house of the #Conti malware syndicate and a sophisticated replacement for the #BazarLoader backdoor! Learn what Sectrio's research team discover about the #malware while analyzing it! Read more: https://t.co/wx40xU8V98
#cyberattack

[#Ransomeware] #Bumblebee 🐝 est un nouveau chargeur de #malwares destiné à supplanter le fameux #Bazarloader, car il utilise une méthode de compromission initiale étonnante et possède des fonctionnalités accrues ajoutées régulièrement.
En savoir +🔎 https://t.co/dkrJmJ2AJF
#BazarLoader #malware is sweeping through at a very quick rate, disguising itself as safe files. With files that look legitimate, what will you do to make sure you’re protecting your company against this new malware?
https://t.co/Hz0LMhLUnU
(2/4)
WIN-799RI0TSTOF - as noted in the below research by @TheDFIRReport, was associated with #BazarLoader / #Diavol ransomware in December 2021.
https://t.co/o7YcE5p5cQ
Diavol Ransomware
➡️Initial Access: Zip->ISO loading BazarLoader
➡️Discovery: Net, Ping, AdFind, Advanced IP Scanner, ShareFinder
➡️C2: #CobaltStrike & #BazarLoader
➡️Lateral Movement: RDP, AnyDesk
➡️Exfil: FileZilla, ufile
➡️Impact: Diavol ransomware
https://t.co/JWZGF83nqu
#ESETresearch The developers of #Bumblebee, a #downloader that is a contender to become #BazarLoader’s successor, started implementing code #obfuscation. They are now encrypting key code strings, such as the list of C&C servers or the name of the campaign (aka “group_name”). 1/5
解析対策技術を使うマルウェアの解析はそうでないものより難しいですが、そうした対策を打ち破るための技術もあります。今回は #BazarLoader マルウェアを例にとり、同マルウェアの解析対策技術2つを破る2つの方法を紹介します。
https://t.co/DXPmluZXYF

#BazarLoader
md5: 31998f5613e344cb5aa66e2e6dff8d07
Filename: result_04-2232.html
HTML --> ZIP ---> ISO ---> .lnk + .dll
Most Popular Users

Elon Musk 
@elonmusk
241.2M followers

Barack Obama 
@barackobama
119.1M followers

Cristiano Ronaldo 
@cristiano
112.8M followers

Donald J. Trump 
@realdonaldtrump
111.8M followers

Narendra Modi 
@narendramodi
107.1M followers

Rihanna 
@rihanna
98.3M followers

NASA 
@nasa
92.3M followers

Justin Bieber 
@justinbieber
91.5M followers

KATY PERRY 
@katyperry
89M followers

Taylor Swift 
@taylorswift13
82.9M followers

Lady Gaga 
@ladygaga
74.4M followers

Virat Kohli 
@imvkohli
71.9M followers

Kim Kardashian 
@kimkardashian
70.4M followers

YouTube 
@youtube
68.8M followers

Neymar Jr 
@neymarjr
64.8M followers

Bill Gates 
@billgates
64.6M followers

The Ellen Show
@theellenshow
62.4M followers

Selena Gomez 
@selenagomez
62.1M followers

CNN 
@cnn
61.8M followers

X 
@x
60.8M followers



















