Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: BAZARCALL / BAZARLOADER
- SENDERS OBSERVED
- dennisegres@mail.com
- HolWaskodh@mail.com
- mistypowell_83@yahoo.com
- SUBJECTS OBSERVED
- You'll be moved to our premium! Your number is VCP6#############.
- Your free period is nearly ended. Your account no VCP6#############. Ready to continue?
- Your premium demo is almost over. Your members account no VCP6#############. All set to move forward?
- LURE PHONE NUMBER
- +1 213 401 2706
- MALDOC LANDING PAGE URLS
- https://zonerphoto.us
- https://vcophoto.us
- MALDOC DOWNLOAD URLS
- https://zonerphoto.us/cancel.php
- MALDOC (XLSB) FILE HASHES
- cancel_sub_VCP6#############.xlsb
- 1760b30f6ed514aa313b0acaa5c842db
- BAZARLOADER PAYLOAD DOWNLOAD URLs
- First call is to:
- http://195.123.235.51
- which does a 302 redirect to:
- http://pshe0pxe339.xyz/xe1t23ym0s.php
- BAZARLOADER FILE HASHES
- TTObk2.dll
- f51f8a949542f723efe21d2a7bc70a55
- BAZARLOADER C2
- https://54.153.8.158/api/info/send
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement