Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL
- SENDER EMAILS
- SUBJECTS
- Do you want to extend your free trial KRB08074994?
- Do you want to extend your free trial KRB24818025?
- Do you want to extend your free trial KRB64474739?
- Do you want to extend your free trial KRB83674096?
- Thank you for using your free trial KRB89216886. Time to move on!
- Thank you for using your free trial KRB98710862. Time to move on!
- Thank you for using your free trial KRM45320547. Time to move on!
- Want to extend your free trial KRB36649250?
- Your free period KRB01627059 is going to end!
- Your free period KRB03186869 is about to end!
- Your free period KRB25140129 is about to end!
- Your free period KRB59003336 is about to end!
- Your free period KRB81670783 is going to end!
- Your free trial BCS28880200 is about to end!
- Your free trial BCS70780324 is about to end!
- Your free trial BCS89771312 is about to end!
- Your free trial BCS94578201 has come to end!
- Your free trial BCS99265033 is about to end!
- Your free trial KRB18052806 is going to end!
- Your free trial KRB19134463 is about to end!
- Your free trial KRB21207644 has come to end!
- Your free trial KRB36157462 is going to end!
- Your free trial KRB40032391 is going to end!
- Your free trial KRB44977300 has come to end!
- Your free trial KRB65078860 is about to end!
- Your free trial KRB69294315 is about to end!
- Your free trial KRB70065583 is going to end!
- Your free trial KRB84282348 has come to end!
- Your free trial KRB89289856 is about to end!
- Your free trial period BCS18065350 is almost over!
- Your free trial period BCS24846953 is almost over!
- Your free trial period KRB03305129 is almost over!
- Your free trial period KRB34158636 is almost over!
- Your free trial period KRB79974962 is almost over!
- Your free trial period KRB98161631 is almost over!
- LURE PHONE NUMBER
- 1 (424) 317 4380
- MALDOC DOWNLOAD URLS
- https://icartservice.net/unsubscribe.html
- https://imedservice.net/unsubscribe.html
- https://imedservice.net/request.php
- https://icartservice.net/request.php
- MALDOC FILE HASHES
- subscription_1616428922.xlsb
- 342cc30e3d3f7e2ec2009da053ae72de
- subscription_1616428795.xlsb
- eabb1f2f43d47c389f9b1fc956819d82
- subscription_1616441147.xlsb
- 1a832d0d189a7ff0f23393d5031060c1
- subscription_1616441102.xlsb
- 4bc7c60bacd4c0e15743821f71d689e3
- PAYLOAD DOWNLOAD URL
- First a post to:
- http://gainme.xyz/campo/t/t
- Then a GET to:
- hgperformance.com.mx/wp-admin/e1.exe
- hgperformance.com.mx/wp-admin/e3.exe
- hgperformance.com.mx/wp-admin/e4.exe
- PAYLOAD FILE HASH
- e1.exe
- a488537f1d95f3cbd78790059dd13bcf
- e3.exe
- acef650d85a7f1e7a9420b74f583d25b
- e4.exe
- 0f319e34515d4cc3c82401bc2a407175
- Renamed to:
- lkag.exe
- a488537f1d95f3cbd78790059dd13bcf
- ADDITIONAL TRAFFIC
- https://35.168.81.240
- ADDITIONAL FILES
- I also found these files in c:\users\public:
- 12.xlsb
- 8d93bea298e32d2d6a2a0783c3662916
- 12.d6
- 8d93bea298e32d2d6a2a0783c3662916
- 12.0
- 1e3f69adf38ca5342b36d4c6ed566c50
- All 3 have MZ headers
- .d6 and .xlsb have the same file hash
Advertisement
Add Comment
Please, Sign In to add comment