ExecuteMalware

2021-05-04 BazarCall IOCs

May 4th, 2021
17,236
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.17 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. Demo stage is now over! Your membership #M02720########### is going to be automatically transferred to premium plan!
  7. Demo stage is now over! Your membership #M02720########### will be automatically transferred to premium plan!
  8. Your demo stage M001200########### will be terminated shortly. Thankfully you made a decision to stick with us!
  9. Your demo stage M001206########### is going to be expired shortly. Thankfully you chose to stick with us!
  10. Your demo stage M001208########### will be expired shortly. Luckily you chose to remain faithful to us!
  11. Your trial period M0012002########### is going to be terminated soon. Thankfully you decided to remain faithful to us!
  12. Your trial period M0012005########### will be expired really soon. Thankfully you chose to remain faithful to us!
  13. Your trial period M0012075########### will be terminated shortly. Luckily for us you made a decision to remain faithful to us!
  14.  
  15. LURE PHONE NUMBER
  16. 1 469 895 7153
  17. 1 313 725 9061
  18.  
  19. MALDOC LANDING PAGE URLS
  20. https://urbancinema.net/
  21. (not yet up)
  22.  
  23. https://bravomovies.net/
  24. https://bravomovies.net/FAQ
  25. https://bravomovies.net/subscribe
  26.  
  27. MALDOC DOWNLOAD URLS
  28. https://bravomovies.net/cancel.php
  29.  
  30. MALDOC (XLSB) FILE HASHES
  31. cancel_sub_M0012005801823488.xlsb
  32. 73d2c5cfaefd74f53487c5b9183892a3
  33.  
  34. CAMPO LOADER DOWNLOAD URLS
  35. http://176.111.174.59/campo/go/go
  36.  
  37. This is renamed and copied here:
  38. C:\ProgramData\6087.exe
  39.  
  40. CAMPO LOADER FILES
  41. 6087.exe
  42. 060e3ac70e8a32d94433290b17784392
  43.  
  44. BAZARLOADER PAYLOAD URL
  45. http://176.111.174.59/uploads/files/krerb.exe
  46.  
  47. BAZARLOADER FILE HASH
  48. krerb.exe
  49. 1c74d51a1d7177bf9b23f6a567adc047
  50.  
  51. BAZARLOADER C2s
  52. https://194.5.249.249/g1_256/bt_64_g1_256
  53. https://45.142.158.201/g1_256/bt_64_g1_256
  54. https://54.212.148.227/g1_256/bt_64_g1_256
  55. https://54.213.70.196/g1_256/bt_64_g1_256
  56.  
  57. SUPPORTING EVIDENCE
  58. https://urlhaus.abuse.ch/url/1194082/
  59.  
Advertisement
Add Comment
Please, Sign In to add comment