2022-05-18 (WEDNESDAY) - TA578 THREAD-HIJACKED EMAILS AND ISO EXAMPLE FOR BUMBLEBEE

NOTES:

ASSOCIATED FILES:

  • 2022-05-18-TA578-malspam-174634-UTC.eml   (4,177 bytes)
  • 2022-05-18-TA578-malspam-184425-UTC.eml   (3,372 bytes)
  • 2022-05-18-TA578-malspam-185413-UTC.eml   (3,210 bytes)
  • 2022-05-18-TA578-malspam-203709-UTC.eml   (3,221 bytes)
  • 2022-05-18-TA578-step-1-storage.googleapis.com-urh21265vg2o9x.appspot.com-g-b-file-d-fZxgV38APHDew.html.txt   (26,933 bytes)
  • 2022-05-18-TA578-step-2-birobixt.com-img-logo.jpg.txt   (861,136 bytes)
  • document.iso   (2,490,368 bytes)
  • documents.lnk   (1,612 bytes)
  • textol.dll   (999,424 bytes)

 

IMAGES


Shown above:  Example of a TA578 thread-hijacked email for Bumblebee malware.

 


Shown above:  Opening link from the email in a web browser returns an ISO file.

 


Shown above:  Contents of downloaded ISO file.

 

Click here to return to the main page.