2021-08-12 (THURSDAY) - STOLEN IMAGES EVIDENCE.ZIP -> BAZARLOADER -> COBALT STRIKE

ASSOCIATED FILES:

  • 2021-08-12-BazarLoader-and-Cobalt-Strike-IOCs.txt   (1,784 bytes)
  • 2021-08-12-BazarLoader-with-Cobalt-Strike.pcap   (14,639,797 bytes)
  • Stolen Images Evidence.js   (23,004 bytes)
  • Stolen Images Evidence.zip   (7,831 bytes)
  • VieFT.dat   (190,984 bytes)

NOTES:

 

IMAGES


Shown above:  Website that delivered Stolen Image Evidence.zip.

 


Shown above:  Traffic from the infection filtered in Wireshark (part 1 of 2).

 


Shown above:  Traffic from the infection filtered in Wireshark (part 2 of 2).

 

Click here to return to the main page.