BuerLoader Updates By Jason Reaves Published: 2021-05-05 · Archived: 2026-04-05 14:37:04 UTC By: Joshua Platt and Jason Reaves Press enter or click to view image in full size Executive Summary Buer task includes domain profiler that appears to have code reuse with the version of Buer being leveraged by TrickBots crew Buers new functionality around loading shellcode[4] as a task allowing for broader functionality against targets without the need for downloading a separate CobaltStrike stager Buers new panel also includes functionality for helping setup distribution for spamming operations and creation of pre-loader objects One of the crews involved in TrickBot has been utilizing Buer[1] loader for sometime now[2,5] to ultimately deliver CobaltStrike[3] and ultimately leading to ransomware. The version of Buer being leveraged for these https://medium.com/walmartglobaltech/buerloader-updates-3e34c1949b96 Page 1 of 7 campaigns has more updates being done to it that appear to be completely designed around an enterprise focus. One such piece that hasn’t been discussed very publicly is that Buer also has a component that is frequently delivered in memory as a task and communicates with the same C2 as Buer but over a different port. DomainInfo Enter Buers ‘DomainInfo’ component which is ultimately designed to profile some information about the infected system and the network that it is joined to. Get Jason Reaves’s stories in your inbox Join Medium for free to get updates from this writer. Remember me for faster sign in The data gathered is constructed into a JSON blob listing ‘Id’, ‘Domains’, ‘Group’ and ‘Server’. https://medium.com/walmartglobaltech/buerloader-updates-3e34c1949b96 Page 2 of 7 Below is the table explaining what data is harvested: After all the data has been collected it will simply post it off to the C2, in doing so a hardcoded User-Agent is passed in. The User-Agent ends up being pretty weird looking but as it turns out the Buer sample that delivered this file had the same User-Agent. https://medium.com/walmartglobaltech/buerloader-updates-3e34c1949b96 Page 3 of 7 Traffic example: POST: /api/v1/modules/domains/dns User-Agent: Rt\x7fnqqf4:35%-Fuuqj2nUmtsj