ExecuteMalware

2021-08-16 BazarLoader IOCs

Aug 16th, 2021 (edited)
16,348
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.92 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARLOADER
  2.  
  3. WEB FORM CONTENTS
  4. name: Amanda
  5. message: Hello! My name is Amanda. Your website or a website that your
  6. organization hosts is infringing on a copyright-protected images owned
  7. by me personally. Check out this document with the links to my images
  8. you used at www.<redacted>.com and my earlier publication to obtain the
  9. evidence of my copyrights. Download it right now and check this out
  10. for yourself:
  11. https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-3dk3nvbv4ju3n.html?alt=media&token=0471b204-69d8-4a6c-914a-31a622163a92&l=105655924057099880
  12. I really believe that you deliberately infringed my legal rights under
  13. 17 U.S.C. Sec. 101 et seq. and could possibly be liable for statutory
  14. damage of up to $130,000 as set forth in Section 504 (c)(2) of the
  15. Digital Millennium Copyright Act (DMCA) therein. This message is
  16. official notification. I demand the removal of the infringing
  17. materials described above. Please be aware as a service provider, the
  18. Digital Millennium Copyright Act requires you, to eliminate and/or
  19. disable access to the infringing content upon receipt of this
  20. particular notice. In case you don't cease the use of the
  21. aforementioned infringing materials a law suit can be initiated
  22. against you. I have a strong self-belief that utilization of the
  23. copyrighted materials mentioned above as allegedly infringing is not
  24. approved by the copyright proprietor, its legal agent, or the
  25. legislation. I swear, under consequence of perjury, that the
  26. information in this message is correct and that I am the legal
  27. copyright proprietor or am authorized to act on behalf of the
  28. proprietor of an exclusive and legal right that is presumably
  29. violated. Best regards, Amanda Mays 08/16/2021
  30.  
  31. MALDOC DOWNLOAD URLS
  32. https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-3dk3nvbv4ju3n.html?alt=media&token=0471b204-69d8-4a6c-914a-31a622163a92&l=105655924057099880
  33.  
  34. https://morungato.space/nerkl23vhb4/
  35.  
  36. https://drive.google.com/uc?export=download&id=19lvLhFngyRrtg-nco6BeSUqgo6oQghBA
  37.  
  38. https://doc-04-bg-docs.googleusercontent.com/docs/securesc/ha0ro937gcuc7l7deffksulhg5h7mbp1/2btpeop445f74euco74tc5r4vlh0q3b2/1629131550000/08811926844747145094/*/19lvLhFngyRrtg-nco6BeSUqgo6oQghBA?e=download
  39.  
  40. MALDOC FILE HASHES
  41. Stolen Images Evidence.zip
  42. ed95f966a0e5866442fcd940f7c55531
  43.  
  44. Which contains:
  45. Stolen Images Evidence.js
  46. 9f4d8898110eaf2acae077b8ea6d6c5e
  47.  
  48. BAZARLOADER PAYLOAD DOWNLOAD URLS
  49. http://meshura.space/333g100/index.php
  50. http://meshura.space/333g100/main.php
  51.  
  52. BAZARLOADER PAYLOAD FILE HASHES
  53. main.php
  54. 962d7236a91febb63b34fa72ab09357e
  55.  
  56. This .dll was renamed and dropped into AppData\Local\Temp
  57.  
  58. tqPuZe.dat
  59. 962d7236a91febb63b34fa72ab09357e
  60.  
  61. BAZARLOADER C2
  62. https://104.248.30.5/static/web/issue
  63. https://104.248.18.107/static/web/issue
  64. https://165.227.136.95/static/web/issue
  65. https://165.227.131.219/static/web/issue
  66.  
Add Comment
Please, Sign In to add comment