2021-09-01 (WEDNESDAY) - TA551 (SHATHAK) BAZARLOADER TO TRICKBOT GTAG ZEV4

ASSOCIATED FILES:

NOTES:

 


Shown above:  Screenshot from a TA551 email from Wednesday 2021-09-01.

 


Shown above:  Retreiving Word doc from the password-protected zip attachment.

 


Shown above:  Screenshot of the Word doc.

 


Shown above:  HTA file and BazarLoader DLL seen after enabling macros.

 


Shown above:  Traffic from an infected Windows host.

 


Shown above:  Trickbot sent over Bazar C2 traffic.

 

Click here to return to the main page.