ExecuteMalware

2021-03-24 BazarCall IOCs

Mar 24th, 2021 (edited)
17,732
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.19 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free trial KJR82250995?
  7. Thank you for using your free trial BCS49108273. Time to move on!
  8. Want to extend your free trial BCS87227489?
  9. Want to extend your free trial BCS94578201?
  10. Your free trial BCS74922261 has come to end!
  11. Your free trial KJR05696670 is going to end!
  12. Your free trial KJR20362849 is going to end!
  13. Your free trial KJR38012845 is going to end!
  14. Your free trial KJR90622295 is going to end!
  15. Your free trial RMN70575496 has come to end!
  16.  
  17. LURE PHONE NUMBER
  18. 1 (213) 261-0445
  19. 1 (661) 501-2041
  20.  
  21. MALDOC DOWNLOAD URLS
  22. https://bluecartservice.com/unsubscribe.html
  23. https://icartservice.org/unsubscribe.html
  24. https://imedservice.org/unsubscribe.html
  25. https://imerservice.net/unsubscribe.html
  26. https://merservice.org/unsubscribe.html
  27.  
  28. https://bluecartservice.com/request.php
  29. https://icartservice.org/request.php
  30. https://imedservice.org/request.php
  31. https://imerservice.net/request.php
  32. https://merservice.org/request.php
  33.  
  34. bluecartservice.com
  35. icartservice.org
  36. imedservice.org
  37. imerservice.net
  38. merservice.org
  39.  
  40. MALDOC FILE HASHES
  41. 04021a582f12c54e1023fdcee600111c
  42. 38c3650fbd0f86a03b6791aebe9d0c46
  43. 3b96e081be068d210a85b55925372567
  44. 412db47e93b22ec47c672910e1f85170
  45. a5e1db7b40b1df187d7c4f227ffb316c
  46. a8640287aac9c6468ac03f412382a839
  47. e318ef00212305129aca499d569a741b
  48. fc310563e9b0628f6b5a8567bf3b5133
  49.  
  50. PAYLOAD DOWNLOAD URL
  51. First a post to:
  52. http://gopigs.xyz/campo/u/u
  53.  
  54. Then downloads:
  55. http://nommac.com/malta-app/Malta/node_modules/postcss-merge-rules/dist/retrsd25.exe
  56.  
  57. PAYLOAD FILE HASH
  58. retrsd25.exe
  59. 78388676e1ebde4576357c3727a51787
  60.  
  61. ADDITIONAL FILES
  62. I also found these files in \Users\public:
  63.  
  64. 42237.j56
  65. 0ddece3ffa94e0acffddf867f001a644
  66.  
  67. 42237.xlsb
  68. 0ddece3ffa94e0acffddf867f001a644
  69.  
  70. 42237.h5
  71. 1462605ccb643532a25098e7fbe323cb
  72.  
  73. And then later:
  74. 42237.j56
  75. c056b7d3999d5110ff1d3bb9c29655b8
  76.  
  77. 42237.xlsb
  78. c056b7d3999d5110ff1d3bb9c29655b8
  79.  
  80. 42237.h5
  81. e80bb5df25aeff934df851df566e3775
  82.  
  83. All have MZ headers
  84. .j56 and .xlsb have the same file hash
Add Comment
Please, Sign In to add comment