Buer Loader provides malware-as-a-service

 

Buer Loader provides malware-as-a-service 
 

  Buer is a malware-as-a-service offering that is used to deliver whatever package the service customer desires, providing initial compromise of targets’ Windows PCs and allowing them to establish a digital beachhead for further malicious activity. Buer has previously been tied to banking trojan attacks and other malware deployments—and now, apparently, has been embraced by ransomware operators. In many ways, Buer is positioned as an alternative to Emotet and Trickbot’s emerging Bazar loader.
“A new modular bot…written in pure C” with command and control (C&C) server code written in .NET Core MVC (which can be run on Linux servers).

Indicators of Compromise


File Hashes


10943b90969722bf359e4b039d2953e02072e03e0a7f1bdb1dea09d9197288b1
32616f41a71fc7a4286736a6fc77da2a555dbc8301a8bd5fbdbab231955a42c5
5b607f001ba62e042344d30b65cad2774df2deb50e0b92c33da85e9338c123c4  
6c7f43434e5db8703c0a47dedeeab976159d8704bfbe2e4ff65405f38d508e9d 

 IP

104.248.83.13    
 

Comments

Popular posts from this blog

Revil Ransomware Targeted Kaseya

BANDOOK(RAT)