Another day, another wave of malware. Although there's plenty to find, I've been focusing on BazarLoader as it comes through various distribution channels. One such channel is the "Stolen Images Evidence" campaign, which Microsoft describes here. This campaign was pushing IcedID as we entered 2021, but it switched to BazarLoader as early as July 2021.
The "Stolen Images Evidence" campaign uses emails generated through contact forms on various websites. So these messages don't originate through normal spam methods. They appear through contact form submissions describing a copyright violation to the intended victim. These form-submitted messages include a Google firebase storage URL in the message text. This malicious link supposedly provides proof of stolen images that resulted in a copyright violation.
Downloaded zip archives
BazarLoader from the JS file
Infection traffic is typical for what we normally see with BazarLoader.
Indicators of Compromise (IOCs)
The following is malware retrieved from an infected Windows host.
Google Firebase URL used to deliver the malicious zip archive:
Malicious domain called when using the above Google Firebase URL:
Bazar C2 traffic:
The associated malware samples have been submitted to bazaar.abuse.ch, and they're available using links from the above SHA256 hashes.
This campaign uses "Stolen Images Evidence" and copyright violation as its primary theme. However, it also used a "DDoS attack proof" theme last month. Either way, this campaign has been fairly active in 2021, and we expect it to continue throughout the rest of this year. It will probably continue into 2022 as well.
Sep 8th 2021
Sep 8th 2021
2 weeks ago