ExecuteMalware

2021-03-22 BazarCall IOCs

Mar 22nd, 2021
5,361
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.21 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free trial KRB08074994?
  7. Do you want to extend your free trial KRB24818025?
  8. Do you want to extend your free trial KRB64474739?
  9. Do you want to extend your free trial KRB83674096?
  10. Thank you for using your free trial KRB89216886. Time to move on!
  11. Thank you for using your free trial KRB98710862. Time to move on!
  12. Thank you for using your free trial KRM45320547. Time to move on!
  13. Want to extend your free trial KRB36649250?
  14. Your free period KRB01627059 is going to end!
  15. Your free period KRB03186869 is about to end!
  16. Your free period KRB25140129 is about to end!
  17. Your free period KRB59003336 is about to end!
  18. Your free period KRB81670783 is going to end!
  19. Your free trial BCS28880200 is about to end!
  20. Your free trial BCS70780324 is about to end!
  21. Your free trial BCS89771312 is about to end!
  22. Your free trial BCS94578201 has come to end!
  23. Your free trial BCS99265033 is about to end!
  24. Your free trial KRB18052806 is going to end!
  25. Your free trial KRB19134463 is about to end!
  26. Your free trial KRB21207644 has come to end!
  27. Your free trial KRB36157462 is going to end!
  28. Your free trial KRB40032391 is going to end!
  29. Your free trial KRB44977300 has come to end!
  30. Your free trial KRB65078860 is about to end!
  31. Your free trial KRB69294315 is about to end!
  32. Your free trial KRB70065583 is going to end!
  33. Your free trial KRB84282348 has come to end!
  34. Your free trial KRB89289856 is about to end!
  35. Your free trial period BCS18065350 is almost over!
  36. Your free trial period BCS24846953 is almost over!
  37. Your free trial period KRB03305129 is almost over!
  38. Your free trial period KRB34158636 is almost over!
  39. Your free trial period KRB79974962 is almost over!
  40. Your free trial period KRB98161631 is almost over!
  41.  
  42. LURE PHONE NUMBER
  43. 1 (424) 317 4380
  44.  
  45. MALDOC DOWNLOAD URLS
  46. https://icartservice.net/unsubscribe.html
  47. https://imedservice.net/unsubscribe.html
  48.  
  49. https://imedservice.net/request.php
  50. https://icartservice.net/request.php
  51.  
  52. MALDOC FILE HASHES
  53. subscription_1616428922.xlsb
  54. 342cc30e3d3f7e2ec2009da053ae72de
  55.  
  56. subscription_1616428795.xlsb
  57. eabb1f2f43d47c389f9b1fc956819d82
  58.  
  59. subscription_1616441147.xlsb
  60. 1a832d0d189a7ff0f23393d5031060c1
  61.  
  62. subscription_1616441102.xlsb
  63. 4bc7c60bacd4c0e15743821f71d689e3
  64.  
  65. PAYLOAD DOWNLOAD URL
  66. First a post to:
  67. http://gainme.xyz/campo/t/t
  68.  
  69. Then a GET to:
  70. hgperformance.com.mx/wp-admin/e1.exe
  71. hgperformance.com.mx/wp-admin/e3.exe
  72. hgperformance.com.mx/wp-admin/e4.exe
  73.  
  74. PAYLOAD FILE HASH
  75. e1.exe
  76. a488537f1d95f3cbd78790059dd13bcf
  77.  
  78. e3.exe
  79. acef650d85a7f1e7a9420b74f583d25b
  80.  
  81. e4.exe
  82. 0f319e34515d4cc3c82401bc2a407175
  83.  
  84. Renamed to:
  85. lkag.exe
  86. a488537f1d95f3cbd78790059dd13bcf
  87.  
  88. ADDITIONAL TRAFFIC
  89. https://35.168.81.240
  90.  
  91. ADDITIONAL FILES
  92. I also found these files in c:\users\public:
  93. 12.xlsb
  94. 8d93bea298e32d2d6a2a0783c3662916
  95.  
  96. 12.d6
  97. 8d93bea298e32d2d6a2a0783c3662916
  98.  
  99. 12.0
  100. 1e3f69adf38ca5342b36d4c6ed566c50
  101.  
  102. All 3 have MZ headers
  103. .d6 and .xlsb have the same file hash
Advertisement
Add Comment
Please, Sign In to add comment