Advertisement
ExecuteMalware

2021-08-02 BazarCall IOCs

Aug 2nd, 2021
11,694
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.06 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL / BAZARLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Car accident claim
  5. Essential reminder! Abandoned place of vehicle accident
  6. Automobile accident reminder
  7.  
  8. SENDERS OBSERVED
  9. Erika Jones <poktadawniatita94@aol.com>
  10. Brittany Rivera <notification@email.sendmemsg.com>
  11. Julie Smith <juliesuperfamily52@aol.com>
  12.  
  13. LURE PHONE NUMBER
  14. +1 646 980 6856
  15.  
  16. EMAIL BODY
  17. Meagher Auto insurer
  18. Re: Abandoned site of automobile accident on
  19. Request No.: <Redacted - recipient name>
  20.  
  21. Greetings, dear L1#########,
  22.  
  23. This notification is accepted as an official notification that compensation is demanded from for the car accident that occurred on 07/23/2021. The full demand amount, after calculating direct payments, is $346.87
  24.  
  25. Please get in touch with us at +1 646 980 6856 Monday to Friday from 9 am to 6 pm. Our customer support is going to help you get the full information about the vehicle accident including videos, images of the automobile plate, and all the other sensitive information about this particular incident.
  26.  
  27. As it was highlighted earlier the location of a automobile accident was left. According to our insurance company's policy, we will have to report this vehicle accident to the police officers in the next 72 hours, please get in touch with us as soon as possible to find a solution for this situation.
  28.  
  29. Warm regards,
  30. The Meagher Agency
  31.  
  32. MALDOC LANDING PAGES
  33. https://meagherinsurance.co/
  34. https://meagherinsurance.co/case
  35.  
  36. MALDOC DOWNLOAD URL
  37. https://meagherinsurance.co/download.php
  38.  
  39. BAZARCALL MALDOC FILE HASHES
  40. case_L##########.xlsb
  41. 8cb6c166f9630a1116df6ed2607b0062
  42.  
  43. BAZARLOADER PAYLOAD DOWNLOAD URL
  44. http://185.82.127.185
  45.  
  46. BAZARLOADER PAYLOAD FILE HASHES
  47. Ra5iI.dll
  48. 9a942c191541825b279466f4c6cbd930
  49.  
  50. BAZARLOADER C2
  51. https://54.177.75.53/out/static/text
  52.  
  53. ADDITONAL STRINGS IN MEMORY
  54. https://54.183.226.207:443
  55. https://64.227.73.19:443
  56. https://64.227.77.91:443
  57.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement