Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL
- SENDER EMAILS
- info@icartservice.com
- info@icartservice.net
- newtonmeddr@ibest.com.br
- suarezrosana@ibest.com.br
- tobema@homebyasa.nl
- tyfoda@testwp.kimze-online.com
- SUBJECTS
- Do you want to extend your free trial KJR82250995?
- Thank you for using your free trial BCS49108273. Time to move on!
- Want to extend your free trial BCS87227489?
- Want to extend your free trial BCS94578201?
- Your free trial BCS74922261 has come to end!
- Your free trial KJR05696670 is going to end!
- Your free trial KJR20362849 is going to end!
- Your free trial KJR38012845 is going to end!
- Your free trial KJR90622295 is going to end!
- Your free trial RMN70575496 has come to end!
- LURE PHONE NUMBER
- 1 (213) 261-0445
- 1 (661) 501-2041
- MALDOC DOWNLOAD URLS
- https://bluecartservice.com/unsubscribe.html
- https://icartservice.org/unsubscribe.html
- https://imedservice.org/unsubscribe.html
- https://imerservice.net/unsubscribe.html
- https://merservice.org/unsubscribe.html
- https://bluecartservice.com/request.php
- https://icartservice.org/request.php
- https://imedservice.org/request.php
- https://imerservice.net/request.php
- https://merservice.org/request.php
- bluecartservice.com
- icartservice.org
- imedservice.org
- imerservice.net
- merservice.org
- MALDOC FILE HASHES
- 04021a582f12c54e1023fdcee600111c
- 38c3650fbd0f86a03b6791aebe9d0c46
- 3b96e081be068d210a85b55925372567
- 412db47e93b22ec47c672910e1f85170
- a5e1db7b40b1df187d7c4f227ffb316c
- a8640287aac9c6468ac03f412382a839
- e318ef00212305129aca499d569a741b
- fc310563e9b0628f6b5a8567bf3b5133
- PAYLOAD DOWNLOAD URL
- First a post to:
- http://gopigs.xyz/campo/u/u
- Then downloads:
- http://nommac.com/malta-app/Malta/node_modules/postcss-merge-rules/dist/retrsd25.exe
- PAYLOAD FILE HASH
- retrsd25.exe
- 78388676e1ebde4576357c3727a51787
- ADDITIONAL FILES
- I also found these files in \Users\public:
- 42237.j56
- 0ddece3ffa94e0acffddf867f001a644
- 42237.xlsb
- 0ddece3ffa94e0acffddf867f001a644
- 42237.h5
- 1462605ccb643532a25098e7fbe323cb
- And then later:
- 42237.j56
- c056b7d3999d5110ff1d3bb9c29655b8
- 42237.xlsb
- c056b7d3999d5110ff1d3bb9c29655b8
- 42237.h5
- e80bb5df25aeff934df851df566e3775
- All have MZ headers
- .j56 and .xlsb have the same file hash
Add Comment
Please, Sign In to add comment