The Defective Domain Generation Algorithm of BazarLoader
Tags
attack-pattern: | Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 Python - T1059.006 |
Common Information
Type | Value |
---|---|
UUID | ce8f3434-bb2b-4362-8fd2-45f58936201c |
Fingerprint | 8a14acb14cd021e1 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 19, 2020, midnight |
Added to db | Aug. 31, 2024, 12:10 a.m. |
Last updated | Nov. 16, 2024, 11:18 a.m. |
Headline | The Defective Domain Generation Algorithm of BazarLoader |
Title | The Defective Domain Generation Algorithm of BazarLoader |
Detected Hints/Tags/Attributes | 26/1/8 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 19 | ✔ | Binary Reverse Engineering Blog | https://bin.re/feed.xml | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 5 | args.date |
|
Details | Domain | 46 | datetime.now |
|
Details | File | 1 | dd45.exe |
|
Details | File | 1 | preview_report.exe |
|
Details | File | 6 | args.dat |
|
Details | md5 | 1 | 18d635a8ca7caefb4f4513650a31efc9 |
|
Details | sha1 | 1 | d555233122a277fb89797ab2293efbe2a0c75f7f |
|
Details | sha256 | 1 | 2e99ed535a9f73bafab151ec409de04c953a0187cb8e4063317617befa09068d |