Advertisement
ExecuteMalware

2021-03-02 Buerloader IOCs

Mar 2nd, 2021
4,090
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.29 KB | None | 0 0
  1. THREAT IDENTIFICATION: BUERLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. order 06688 Package
  5. order 230126 Parcel
  6. order 23279192 Parcel
  7. order 257502 Parcel
  8. order 3490948 Package
  9. order 4260217 Package
  10. order 4342788 Package
  11. order 4556088 Parcel
  12. order 47433 Parcel
  13. order 599800 Parcel
  14. order 6123190 Parcel
  15. order 76225024 Package
  16. order 921751 Package
  17. order 98927189 Parcel
  18. order 99272 Parcel
  19.  
  20. SENDERS OBSERVED
  21. Bailey@kiekhafer.com
  22. Brooks@kiekhafer.com
  23. Carter@fhri.net
  24. Hughes@kiekhafer.com
  25. Jackson@kiekhafer.com
  26. Jones@kiekhafer.com
  27. Kelly@fhri.net
  28. King@kiekhafer.com
  29. Lopez@fhri.net
  30. Morgan@fhri.net
  31. Parker@kiekhafer.com
  32. Reed@fhri.net
  33. Rodriguez@kiekhafer.com
  34. Thomas@kiekhafer.com
  35. Thompson@kiekhafer.com
  36.  
  37. BUERLOADER MALDOC FILE HASHES
  38. invoice.jnlp
  39. 67e9e29dde633fc31d03a9075c53788d
  40.  
  41. 2021invoice.jnlp
  42. e38e0a050e1d1e47b5b9e30c65c6593e
  43.  
  44. invoice.jar
  45. cee1f62d1cf8c508faf263d61e6cf27f
  46.  
  47. BUERLOADER PAYLOAD DOWNLOAD
  48. http://invoicesecure.net/documents/invoice.jar
  49. http://pdfsecure.net/docs/2021invoice.jar
  50. http://invoicesecure.net/img/footer.jpg
  51.  
  52. BUERLOADER PAYLOAD FILE HASHES
  53. footer.jpg
  54. 19ca9bf5eebc9e2f0bd3230f262348fd
  55.  
  56. drvr32.exe
  57. 19ca9bf5eebc9e2f0bd3230f262348fd
  58.  
  59. BUERLOADER C2
  60. http://verstudiosan.com/
  61.  
  62. SUPPORTING EVIDENCE
  63. https://app.any.run/tasks/1e73e6b5-1f70-4a00-a131-a5d34561c4df/
  64.  
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement