ExecuteMalware

2021-05-18 BazarCall IOCs

May 18th, 2021
16,247
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.15 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. JPL82128213###### Your trial offer will expire in 48 hours. The Premium is going to be instantly extended.
  7. JPL82158040###### The free trial expires in 24 hours. The Premium subscription will be automatically prolonged.
  8. JPL82180618###### The demo ends in 48 hours. The Premium subscription will be instantly extended.
  9.  
  10. LURE PHONE NUMBER
  11. +1 720 738 4572
  12.  
  13. MALDOC LANDING PAGE URLS
  14. https://justpayless.net/
  15.  
  16. MALDOC DOWNLOAD URLS
  17. https://justpayless.net/cancel.php
  18.  
  19. MALDOC (XLSB) FILE HASHES
  20. cancel_sub_JPL82158040######.xlsb
  21. a3b451dfbd67d0f701982b5f53906869
  22.  
  23. ADDITIONAL/CAMPO LOADER FILES
  24. 4802545.xs2
  25. cfb94c893280fd1edd40a4c74031727a
  26.  
  27. 4802545.xlsb
  28. e3c91eeeec07ed08ff35991cd1f8926d
  29.  
  30. 4802545.xs1
  31. e3c91eeeec07ed08ff35991cd1f8926d
  32.  
  33. CAMPO LOADER PAYLOAD DOWNLOAD URLS
  34. http://saw1.xyz/campo/s/w
  35.  
  36. BAZARLOADER PAYLOAD URL
  37. http://thesmartmoneyinstitute.com/wpp.exe
  38.  
  39. BAZARLOADER FILE HASHES
  40. wpp.exe
  41. 055c79de6e3f255beade0b35a0a2cd17
  42.  
  43. Renamed and copied to:
  44. \users\all\ywgbs
  45.  
  46. ywgbs.exe
  47. 055c79de6e3f255beade0b35a0a2cd17
  48.  
  49. BAZAR LOADER C2
  50. 54.193.66.166
  51.  
Advertisement
Add Comment
Please, Sign In to add comment