Malware
BazarBackdoor
aka BEERBOT · KEGTAP · Team9Backdoor · bazaloader · bazarloader
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor.
BazarBackdoor is a small backdoor, probably by a TrickBot "spin-off" like anchor. Its called team9 backdoor (and the corresponding loader: team9 restart loader).
For now, it exclusively uses Emercoin domains (.bazar), thus the naming. FireEye uses KEGTAP as name for BazarLoader and BEERBOT for BazarBackdoor.
Family metadata imported from Malpedia (Fraunhofer FKIE).