ExecuteMalware

2021-06-10 BazarCall IOCs

Jun 11th, 2021
19,847
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.93 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZARCALL / BAZARLOADER
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. You'll be moved to our premium! Your number is VCP6#############.
  7. Your free period is nearly ended. Your account no VCP6#############. Ready to continue?
  8. Your premium demo is almost over. Your members account no VCP6#############. All set to move forward?
  9.  
  10. LURE PHONE NUMBER
  11. +1 213 401 2706
  12.  
  13. MALDOC LANDING PAGE URLS
  14. https://zonerphoto.us
  15. https://vcophoto.us
  16.  
  17. MALDOC DOWNLOAD URLS
  18. https://zonerphoto.us/cancel.php
  19.  
  20. MALDOC (XLSB) FILE HASHES
  21. cancel_sub_VCP6#############.xlsb
  22. 1760b30f6ed514aa313b0acaa5c842db
  23.  
  24. BAZARLOADER PAYLOAD DOWNLOAD URLs
  25. First call is to:
  26. http://195.123.235.51
  27.  
  28. which does a 302 redirect to:
  29. http://pshe0pxe339.xyz/xe1t23ym0s.php
  30.  
  31. BAZARLOADER FILE HASHES
  32. TTObk2.dll
  33. f51f8a949542f723efe21d2a7bc70a55
  34.  
  35. BAZARLOADER C2
  36. https://54.153.8.158/api/info/send
Advertisement
Add Comment
Please, Sign In to add comment