ExecuteMalware

2020-10-15 Bazar IOCs

Oct 15th, 2020
4,192
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.55 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZAR
  2.  
  3. SUBJECTS OBSERVED
  4. RE: <Firstname>, i'm waiting for a call
  5. RE: <Company Name> termination list
  6. Re: my call
  7.  
  8. SENDERS OBSERVED
  9.  
  10. BAZAR PAYLOAD FILE HASHES
  11. Review_Report15-10.exe
  12.  
  13. 30433602504955fdfd1c94076dec5a65
  14. 5965347bdea813b619221ed7b0c029ff
  15.  
  16. DIGITAL SIGNATURE
  17. Rumikon LLC
  18.  
  19. PAYLOAD DESCRIPTION
  20. YUVPlayer
  21. version 4.0.0.0
  22.  
  23. LANDING PAGE URLS
  24. https://docs.google.com/document/d/e/2PACX-1vQbq8_5WK2-w14EUcVjQiFWg2KZeeU_jmV-LmzkyR5qXg61JlZNBB-PcYyQHKIhk8oHoTLYPec8WxrL/pub
  25. https://docs.google.com/document/d/e/2PACX-1vQhfrsWRcG6_9XyhKcPtZCaO3qDNPnJtZStnf0m_vnkXdJuBPfmp_ErZqXzbg7tA0TLqWo7Vmh733aL/pub
  26. https://docs.google.com/document/d/e/2PACX-1vTrci79cdf1ueJ1WqwH3L96hJ2i1XVV4Wr4TszuqQINDV_dY9Xk_Ys52Xhj9dpTT0UfftuKDA4SqhNz/pub
  27.  
  28. PAYLOAD DOWNLOAD URLS
  29. https://public.3.basecamp.com/p/nmuDgM49Fu7uUFRMArxkh8NC/upload/download/Review_Report15-10.exe?disposition=attachment
  30. https://bc3-production-us-east-2.s3.us-east-2.amazonaws.com/95qu1hcj28xhfgkdm1w4e1gzxi6z?response-content-disposition=attachment%3B%20filename%3D%22Review_Report15-10.exe%22%3B%20filename%2A%3DUTF-8%27%27Review_Report15-10.exe&response-content-type=application%2Fx-ms-dos-executable&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS5PME4CT5QW2PJJU%2F20201015%2Fus-east-2%2Fs3%2Faws4_request&X-Amz-Date=20201015T183450Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&X-Amz-Signature=974fbb338afa9721f20d47ad983a0bd6447992f8e89b8248c6a7b88e5a5aee05
  31.  
  32. https://public.3.basecamp.com/p/1TUQhSUNsXxZFhhNWZSyfpCo/upload/download/Review_Report15-10.exe?disposition=attachment
  33. https://bc3-production-us-east-2.s3.us-east-2.amazonaws.com/ct9zgslmldejqvmla023amjn9jmi?response-content-disposition=attachment%3B%20filename%3D%22Review_Report15-10.exe%22%3B%20filename%2A%3DUTF-8%27%27Review_Report15-10.exe&response-content-type=application%2Fx-ms-dos-executable&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Credential=AKIAS5PME4CT5QW2PJJU%2F20201015%2Fus-east-2%2Fs3%2Faws4_request&X-Amz-Date=20201015T183619Z&X-Amz-Expires=86400&X-Amz-SignedHeaders=host&X-Amz-Signature=c761f000efa4966f686ba46cc977ff3653dd3ab5f752ed2f94ac802b94d3b5ca
  34. https://sb-ssl.google.com/safebrowsing/clientreport/download?key=%GOOGLE_SAFEBROWSING_API_KEY%
  35.  
  36. BAZAR C2
  37. https://54.245.74.151
  38. resolves to:
  39. titlecs.com
  40.  
  41. https://18.188.194.80
  42. resolves to:
  43. labelcs.com
Add Comment
Please, Sign In to add comment