Bumblebee Loader Resurfaces in New Campaign
Tags
cmtmf-attack-pattern: Automated Exfiltration Develop Capabilities Obtain Capabilities Scheduled Task/Job Stage Capabilities
maec-delivery-vectors: Watering Hole
attack-pattern: Data Asymmetric Cryptography - T1521.002 Asymmetric Cryptography - T1573.002 Botnet - T1583.005 Botnet - T1584.005 Client Configurations - T1592.004 Commonly Used Port - T1436 Control Panel - T1218.002 Credentials From Password Stores - T1555 Credentials From Web Browsers - T1555.003 Credentials From Web Browsers - T1503 Data From Local System - T1533 Develop Capabilities - T1587 Domain Generation Algorithms - T1637.001 Domain Generation Algorithms - T1568.002 Domain Generation Algorithms - T1520 Domain Generation Algorithms - T1483 Domains - T1583.001 Domains - T1584.001 Dynamic Resolution - T1637 Dynamic Resolution - T1568 Encrypted Channel - T1521 Encrypted Channel - T1573 Exfiltration Over C2 Channel - T1646 Gather Victim Host Information - T1592 Ip Addresses - T1590.005 Malicious File - T1204.002 Malicious Link - T1204.001 Malvertising - T1583.008 Malware - T1587.001 Malware - T1588.001 Non-Standard Port - T1509 Non-Standard Port - T1571 Obtain Capabilities - T1588 Phishing - T1660 Phishing - T1566 Scheduled Task - T1053.005 Scheduled Task/Job - T1603 Stage Capabilities - T1608 Symmetric Cryptography - T1521.001 Symmetric Cryptography - T1573.001 Tool - T1588.002 Upload Malware - T1608.001 Upload Tool - T1608.002 Automated Exfiltration - T1020 Commonly Used Port - T1043 Data Encoding - T1132 Data From Local System - T1005 Data Obfuscation - T1001 Exfiltration Over Command And Control Channel - T1041 Scheduled Task - T1053 User Execution - T1204 Commonly Used Port User Execution
Common Information
Type Value
UUID 873e0da9-6483-4a74-84c5-53f0f99d1ec1
Fingerprint a184a9d983be97e1
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 15, 2023, midnight
Added to db Aug. 31, 2024, 2:40 a.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Bumblebee Loader Resurfaces in New Campaign
Title Bumblebee Loader Resurfaces in New Campaign
Detected Hints/Tags/Attributes 121/3/25
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 138 Intel471 https://intel471.com/blog/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 8
4shared.com
Details File 3
replace.exe
Details File 240
wmic.exe
Details File 137
conhost.exe
Details MITRE ATT&CK Techniques 5
T1592.004
Details MITRE ATT&CK Techniques 96
T1587.001
Details MITRE ATT&CK Techniques 42
T1588.001
Details MITRE ATT&CK Techniques 59
T1588.002
Details MITRE ATT&CK Techniques 49
T1608.001
Details MITRE ATT&CK Techniques 15
T1608.002
Details MITRE ATT&CK Techniques 409
T1566
Details MITRE ATT&CK Techniques 106
T1204.001
Details MITRE ATT&CK Techniques 365
T1204.002
Details MITRE ATT&CK Techniques 275
T1053.005
Details MITRE ATT&CK Techniques 125
T1555.003
Details MITRE ATT&CK Techniques 534
T1005
Details MITRE ATT&CK Techniques 96
T1132
Details MITRE ATT&CK Techniques 75
T1001
Details MITRE ATT&CK Techniques 25
T1568.002
Details MITRE ATT&CK Techniques 115
T1571
Details MITRE ATT&CK Techniques 130
T1573.001
Details MITRE ATT&CK Techniques 74
T1573.002
Details MITRE ATT&CK Techniques 102
T1020
Details MITRE ATT&CK Techniques 422
T1041
Details Url 1
https://webdav.4shared