ExecuteMalware

2021-03-30 BazarCall IOCs

Mar 30th, 2021
24,502
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.20 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free period ###########?
  7. Do you want to extend your free trial ###########?
  8. Free period for ############ will come to the end end in 3 days
  9. Free trial period for ############ ends in three days
  10. Free trial period for ############ will end in 3 days
  11. Your free period ########### is about to end!
  12. Your free trial ########### is about to end!
  13.  
  14. LURE PHONE NUMBER
  15. Not available
  16.  
  17. MALDOC DOWNLOAD URLS
  18. https://buyimers.us/unsubscribe.html
  19. https://geticart.us/unsubscribe.html
  20. https://getmers.us/unsubscribe.html
  21. https://gobcs.us/unsubscribe.html
  22. https://goimed.us/unsubscribe.html
  23.  
  24. buyimers.us
  25. geticart.us
  26. getmers.us
  27. gobcs.us
  28. goimed.us
  29.  
  30. MALDOC (XLSB) FILE HASHES
  31. 09740a9d5d1b3d09d64d22d019567784
  32. 1974d98db0e8867165b008f7c46404a1
  33. 5a8f6aa70fae15ba88c0c159c30f923d
  34. cdd3aacf99acd2a4e339914c480a6afd
  35.  
  36. LURE PHONE NUMBERS
  37. Unknown
  38.  
  39. PAYLOAD DOWNLOAD URLS
  40. http://beauty1.xyz/campo/l/l1
  41.  
  42. ADDITONAL PAYLOAD FILE HASHES
  43. 1163.pk9
  44. dd6cdec2609c165cc64b3bc22be5fe20
  45.  
  46. 1163.ph5
  47. 99bfec83b97bd216e06117c6468b19db
  48.  
  49. 1163.xlsb
  50. 99bfec83b97bd216e06117c6468b19db
Advertisement
Add Comment
Please, Sign In to add comment