Light

Episode #885 Quiz

THE BUMBLEBEE LOADER
Date: 2022-08-23 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

Bumblebee is a phishing-delivered malware loader using ISO archives, LNK shortcuts, and living-off-the-land binaries like odbcconf.exe, fodhelper.exe, reg.exe, procdump64.exe, and rclone.exe to inject Meterpreter and Cobalt Strike, escalate via Zerologon, dump LSASS and registry hives, steal ntds.dit, enable lateral movement, persistence, and exfiltration.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What specific Windows utility does the Bumblebee LNK file invoke to load the initial DLL payload via a response file?
Question 2: Which pair of existing Windows executables were spawned and then injected with Meterpreter and Cobalt Strike, respectively?
Question 3: Which exploit did Bumblebee load to perform privilege escalation before continuing its post-exploitation sequence?
Question 4: Which three registry hives did Bumblebee save with reg.exe before compressing and exfiltrating them?
Question 5: According to the timeline Cybereason compiled, how long did Bumblebee's observed intrusion take from initial access to completion of Rclone exfiltration?
Cancel