ExecuteMalware

2021-04-08 BazarCall IOCs

Apr 8th, 2021
17,305
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.51 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Your premium plan demo expires in 24 hours 0408########
  7. Your current premium demo expires in 48 hours 0408########
  8. Your current premium plan trial ends in 24 hours 0408########
  9. Your current premium plan trial ends in 24 hours 0408########
  10. Your premium demo expires in 3 days 0408#########
  11. Your current premium plan trial ends in 24 hours 0408########
  12. Your current premium trial ends in 48 hours 0408########
  13. Your current premium trial expires in 3 days 0408########
  14.  
  15. LURE PHONE NUMBER
  16. +1 901 584 0490
  17.  
  18. MALDOC LANDING PAGE URLS
  19. https://bookpoint.us
  20. https://bookspoint.us
  21. https://pointbook.us
  22. https://pointbooks.us
  23. https://subsbookpoint.us
  24. https://worldbookpoint.com
  25.  
  26. bookpoint.us
  27. bookspoint.us
  28. pointbook.us
  29. pointbooks.us
  30. subsbookpoint.us
  31. worldbookpoint.com
  32.  
  33. MALDOC DOWNLOAD URLS
  34. https://bokpoint.xyz/unsubscribe
  35. https://bokspoint.xyz/unsubscribe
  36. https://pointbok.xyz/unsubscribe
  37. https://pointboks.xyz/unsubscribe
  38.  
  39. bokpoint.xyz
  40. bokspoint.xyz
  41. pointbok.xyz
  42. pointboks.xyz
  43.  
  44. MALDOC (XLSB) FILE HASHES
  45. 713ff91d0faecdc317dbdb22cf30afe3
  46. 7c06f05b2d96542bc7a6997c5e3f4cb4
  47. 9d39f307b0d6276450038cca7568b2cc
  48. a18c5031cb91caf0818448ec313773f5
  49. dd0068e6af3b638e96b09a2e0ec6f051
  50.  
  51. PAYLOAD DOWNLOAD URLS
  52. http://dance4.xyz/campo/d8/d9
  53.  
  54. ADDITIONAL DROPPED FILES
  55. 14118.doy
  56. 61f9ff7edf0a1ff6888e541124226553
  57.  
  58. 14118.xlsb
  59. 61f9ff7edf0a1ff6888e541124226553
  60.  
  61. 14118.biy
  62. 0d90eb265cfe49b20037673845bd0c3c
  63.  
Advertisement
Add Comment
Please, Sign In to add comment