ExecuteMalware

2021-03-25 BazarCall xlsb IOCs

Mar 25th, 2021
17,387
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.15 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL - .xlsb Edition
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free trial KMR00418116?
  7. Do you want to extend your free trial KMR13605781?
  8. Do you want to extend your free trial KMR28241534?
  9. Do you want to extend your free trial KMR38657965?
  10. Do you want to extend your free trial KMR47187437?
  11. Do you want to extend your free trial KMR59049185?
  12. Do you want to extend your free trial KMR87914354?
  13. Thank you for using your free trial KMR28819573. Time to move on!
  14. Thank you for using your free trial KMR45337745. Time to move on!
  15. Thank you for using your free trial KMR46267140. Time to move on!
  16. Thank you for using your free trial KMR59828873. Time to move on!
  17. Thank you for using your free trial KMR59971971. Time to move on!
  18. Your free period KMR03984752 is going to end!
  19. Your free period KMR08015658 is going to end!
  20. Your free period KMR24280432 is going to end!
  21. Your free period KMR56295629 is going to end!
  22. Your free period KMR59244107 is going to end!
  23. Your free period KMR83928445 is going to end!
  24. Your free trial BCS18065350 has come to end!
  25. Your free trial KJR21262654 is going to end!
  26. Your free trial KMR08379642 is about to end!
  27. Your free trial KMR32300989 is going to end!
  28. Your free trial KMR54513846 is going to end!
  29. Your free trial KMR69190965 is going to end!
  30. Your free trial period BCS10146263 is almost over!
  31. Your free trial period BCS72395253 is almost over!
  32. Your free trial period KMR18215288 is almost over!
  33. Your free trial period KMR69309458 is almost over!
  34. Your free trial period KMR79233861 is almost over!
  35.  
  36. LURE PHONE NUMBER
  37. 1 (209) 554 3767
  38.  
  39. MALDOC DOWNLOAD URLS
  40. https://bluecartservice.com/unsubscribe.html
  41. https://icartservice.org/unsubscribe.html
  42. https://imedservice.org/unsubscribe.html
  43. https://imerservice.net/unsubscribe.html
  44. https://merservice.org/unsubscribe.html
  45. https://edurock.org/page-help-&-support-details.html
  46.  
  47. https://bluecartservice.com/request.php
  48. https://icartservice.org/request.php
  49. https://imedservice.org/request.php
  50. https://imerservice.net/request.php
  51. https://merservice.org/request.php
  52.  
  53. bluecartservice.com
  54. edurock.org
  55. icartservice.org
  56. imedservice.org
  57. imerservice.net
  58. merservice.org
  59.  
  60. MALDOC FILE HASHES
  61. subscription_1616701470.xlsb
  62. 6deb0347177942b01645fb3eaffcaaa3
  63.  
  64. subscription_1616701458.xlsb
  65. 98438a323332d7f284414705bfbd6c1d
  66.  
  67. subscription_1616701481.xlsb
  68. e99d785bb13f00307dba75071da7bddb
  69.  
  70. PAYLOAD DOWNLOAD URLS
  71. http://whynt.xyz/campo/w/w
  72. POSTs ping
  73.  
  74. then downloads from:
  75. http://whynt.xyz/uploads/files/dl8x64.exe
  76.  
  77. PAYLOAD FILE HASH
  78. dl8x64.exe
  79. b5cb5ac79b76d8db06f631e4ab461074
  80.  
  81. ADDITIONAL/C2 TRAFFIC
  82. https://3.89.160.167
  83.  
  84. ADDITIONAL FILES
  85. Additional files
  86. 1616183460
  87. 91ee2afefdf066eae3aead061a8075ed
  88.  
  89. Found in \Users\Public
  90. 12394.xps
  91. 256bd88292afefc1a17a96970ff6bbfe
  92.  
  93. 12394.xlsb
  94. 256bd88292afefc1a17a96970ff6bbfe
  95.  
  96. 12394.fl5
  97. 5e61a7988375efe18897ff264b7c81b8
  98.  
  99. STRINGS RUNNING IN MEMORY
  100. C:\project\kerbwe 8\Bin\x64\ReleaseDLL\degx64.pdb
  101. /studio/cut_the_crup
  102.  
  103. More references to "Amadey"
Advertisement
Add Comment
Please, Sign In to add comment