ExecuteMalware

2021-07-29 BazarCall IOCs

Jul 29th, 2021
17,163
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.83 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL / BAZARLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Automobile accident automatic notification
  5. Automobile accident demand notification
  6. Important facts and figures about the abandoned site of an auto accident
  7.  
  8. SENDERS OBSERVED
  9.  
  10. LURE PHONE NUMBER
  11. +1 646 980 6856
  12.  
  13. EMAIL BODY
  14. Meagher Insurance Insurance provider
  15. Re: Left place of car accident on 07.22.2021
  16. Case Id: L02########
  17.  
  18. Dear valued Richard Sinaiko,
  19. This notification is accepted as an authenticated notification that bank payment has been demanded from for the car accident that has taken place on 07.22.2021. The total request amount, after calculating direct payments, is $346.87
  20. You need to call us at +16646998066856
  21. Monday to Friday from 9 am to 6 pm. Our customer support is going to help you get the full information regarding the accident along with video materials, photos of the car plate, and all the other sensitive information regarding this certain incident.
  22. As it was highlighted earlier the location of a vehicle accident was left. According to our insurance policy, we'll have to trasfer this accident to the police after 3 days, please give us a call without delay to find a solution for this situation.
  23.  
  24. Thank you,
  25. Meagher Insurance Insurance company
  26.  
  27. MALDOC LANDING PAGES
  28. https://meagherinsurance.us/
  29. https://meagherinsurance.us/case
  30.  
  31. MALDOC DOWNLOAD URL
  32. https://meagherinsurance.us/download.php
  33.  
  34. BAZARCALL MALDOC FILE HASHES
  35. case_L0########.xlsb
  36. 161233e9e0539f3ab18b46fd74cb548e
  37.  
  38. BAZARLOADER PAYLOAD DOWNLOAD URL
  39. http://185.82.127.62
  40.  
  41. BAZARLOADER PAYLOAD FILE HASHES
  42. (This is just certutil renamed)
  43. HIUbB9XNu.exe
  44. 0d52559aef4aa5eac82f530617032283
  45.  
  46. HIUbB9XNu.dll
  47. abe854ec330ff4c632806d9493a0e2d1
  48.  
  49. BAZARLOADER C2
  50. https://13.52.241.196/req/proc
  51.  
Advertisement
Add Comment
Please, Sign In to add comment