Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL
- SENDERS OBSERVED
- no-reply@justpayless.com
- SUBJECTS OBSERVED
- JPL82128213###### Your trial offer will expire in 48 hours. The Premium is going to be instantly extended.
- JPL82158040###### The free trial expires in 24 hours. The Premium subscription will be automatically prolonged.
- JPL82180618###### The demo ends in 48 hours. The Premium subscription will be instantly extended.
- LURE PHONE NUMBER
- +1 720 738 4572
- MALDOC LANDING PAGE URLS
- https://justpayless.net/
- MALDOC DOWNLOAD URLS
- https://justpayless.net/cancel.php
- MALDOC (XLSB) FILE HASHES
- cancel_sub_JPL82158040######.xlsb
- a3b451dfbd67d0f701982b5f53906869
- ADDITIONAL/CAMPO LOADER FILES
- 4802545.xs2
- cfb94c893280fd1edd40a4c74031727a
- 4802545.xlsb
- e3c91eeeec07ed08ff35991cd1f8926d
- 4802545.xs1
- e3c91eeeec07ed08ff35991cd1f8926d
- CAMPO LOADER PAYLOAD DOWNLOAD URLS
- http://saw1.xyz/campo/s/w
- BAZARLOADER PAYLOAD URL
- http://thesmartmoneyinstitute.com/wpp.exe
- BAZARLOADER FILE HASHES
- wpp.exe
- 055c79de6e3f255beade0b35a0a2cd17
- Renamed and copied to:
- \users\all\ywgbs
- ywgbs.exe
- 055c79de6e3f255beade0b35a0a2cd17
- BAZAR LOADER C2
- 54.193.66.166
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement