pandazheng

2021-04-15 BazarCall IOCs

Apr 15th, 2021
190
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. 0413########. All set to go for a premium plan?
  7.  
  8. LURE PHONE NUMBER
  9. +1 816 307 4271
  10.  
  11. MALDOC LANDING PAGE URLS
  12. https://readebook.us
  13.  
  14. MALDOC DOWNLOAD URLS
  15. https://readebook.us/request.php
  16.  
  17. MALDOC (XLSB) FILE HASHES
  18. subscription_1618516110.xlsb
  19. d2edbd5bd63e2f84ab746886e3b99f74
  20.  
  21. PAYLOAD DOWNLOAD URLS
  22. UNKNOWN
  23.  
  24. ADDITIONAL DROPPED FILES
  25. 105011.oop
  26. 3c79791ee7bbb25eb4139886bb27038d
  27.  
  28. 105011.xlsb
  29. 3c79791ee7bbb25eb4139886bb27038d
  30.  
  31. 105011.gof
  32. 2ecee3dd510442f9b28d62a339a6b7a0
  33.  
Advertisement
Add Comment
Please, Sign In to add comment