ExecuteMalware

2020-10-13 Bazar IOCs

Oct 13th, 2020
2,886
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.93 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZAR
  2.  
  3. SUBJECTS OBSERVED
  4. Re: my call
  5.  
  6. SENDERS OBSERVED
  7. sale@globalcashier[.]net
  8. assist@visavirtualbox[.]com
  9. tech@2brightlights[.]com
  10. team@visavirtualbox[.]com
  11. ticket@floridastatedivorce[.]com
  12. sale@littlernews[.]us
  13. team@thinkyoucandraw[.]info
  14.  
  15. BAZAR PAYLOAD FILE HASHES
  16. Report13-10[.]exe
  17. cbdad2d72c1baacebe006d568d7859df
  18.  
  19. DIGITAL SIGNATURE
  20. SNAB-RESURS, OOO
  21.  
  22. LANDING PAGE URLS
  23. hxxps://docs[.]google[.]com/document/d/e/2PACX-1vQhfrsWRcG6_9XyhKcPtZCaO3qDNPnJtZStnf0m_vnkXdJuBPfmp_ErZqXzbg7tA0TLqWo7Vmh733aL/pub
  24.  
  25. BAZAR C2
  26. hxxps://3[.]137[.]180[.]197/
  27.  
  28. This resolves to: cuprinc[.]com
  29.  
  30. ADDITIONAL PAYLOADS
  31. hxxps://34[.]221[.]202[.]231/bont/vnt
  32. hxxps://34[.]221[.]202[.]231/bont/past
  33.  
  34. ADDITIONAL FILE HASHES
  35. ZIh3aplxwVwlJsyd-M6v
  36. addccf7798728f7f661e0f46bc661511
  37.  
  38. iHzlat3KGi0b7oNw1h18
  39. 09bd533db6f05ad05f5414d2101e96f2
  40.  
  41. SUPPORTING EVIDENCE
  42. https://twitter.com/James_inthe_box/status/1316009750086123523
Add Comment
Please, Sign In to add comment