ExecuteMalware

2021-06-18 BazarCall IOCs

Jun 18th, 2021
19,479
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.09 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZARCALL / BAZARLOADER
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. Your demo expires really soon, VC###############. Your premium will instantly re-new itself.
  7. Your demo stage is almost over. Your account # VC###############. All set to continue?
  8. Your demo stage is almost over. Your account no VC###############. All set to move ahead?
  9. Your free trial expires really soon, VC###############. Your premium plan will immediately re-new itself.
  10. Your free trial expires really soon, VC###############. Your premium will instantly renew itself.
  11. Your free trial expires soon, VC###############. Your premium plan will instantly re-new itself.
  12. Your free trial version ends soon, VC###############. Your premium plan will instantly renew itself.
  13. Your free trial version ends soon, VC###############. Your premium will immediately re-new itself.
  14. Your free trial version expires really soon, VC###############. Your premium will instantly re-new itself.
  15. Your free trial version will expire really soon, VC###############. Your premium will immediately re-new itself.
  16. Your free trial version will expire really soon, VC###############. Your premium plan will immediately renew itself.
  17. Your free trial version will expire very soon, VC###############. Your membership will immediately renew itself.
  18. Your premium demo is almost ended. Your account no. VC###############. Ready to move forward?
  19. Your premium trial is almost ended. Your user account # VC###############. Ready to continue?
  20. Your premium trial is nearly over. Your account number VC###############. Ready to continue?
  21. Your trial offer expires very soon, VC###############. Your premium plan will instantly renew itself.
  22. Your trial offer will expire soon, VC###############. Your premium plan will immediately re-new itself.
  23. Your trial period is almost ended. Your user account id VC###############. All set to move forward?
  24. Your trial period is nearly ended. Your member's account no. VC###############. Ready to move forward?
  25. Your trial period is nearly ended. Your user account # VC###############. Ready to continue?
  26. Your trial period is nearly over. Your membership no VC###############. All set to move ahead?
  27.  
  28. EMAIL BODY
  29. Dear valuable <First> <Last>,
  30.  
  31. The information below will provide you with details about your premium:
  32.  
  33. Purchase id: VC###############
  34. Subscriber full name: <First> <Last>
  35. ZonerPhoto Premium plan/once a month: $59.99*
  36.  
  37. When the trial period runs out, you will be instantly transferred to the premium subscription.
  38.  
  39. The billing information you have indicated at initial registration is going to be used for your membership prolongation. You literally do not need to do anything at all to become our premium user.
  40.  
  41. Still have queries or perhaps you would like to change your premium? Simply call us at +1 213 401 2706
  42.  
  43. ZonerPhoto is getting over TEN thousand users from every part of the world every single day. We provide our customers with the latest photoshop technologies. Croping and editing images has never been that simple!
  44.  
  45. We really hope you will appreciate our photoshop services!
  46.  
  47. ZonerPhoto
  48.  
  49. LURE PHONE NUMBER
  50. +1 213 401 2706
  51.  
  52. MALDOC LANDING PAGE URLS
  53. https://vcophotos.us
  54.  
  55. MALDOC DOWNLOAD URLS
  56. https://vcophotos.us/cancel.php
  57.  
  58. MALDOC (XLSB) FILE HASHES
  59. cancel_sub_VC###############.xlsb
  60. 63fafcb09025a7a2e797a34934d1c3a3
  61.  
  62. BAZARLOADER PAYLOAD DOWNLOAD URLs
  63. First call is to:
  64. http://195.123.247.68/
  65.  
  66. which does a 302 redirect to:
  67. http://j107dnv1y4vffm.xyz/config.php
  68.  
  69. BAZARLOADER FILE HASHES
  70. SoDm7jQ.dll
  71. 7eae124f434ab35881285de9374775de
  72.  
  73. BAZARLOADER C2
  74. https://13.56.226.25/food/breakfast
Advertisement
Add Comment
Please, Sign In to add comment