ExecuteMalware

2021-06-15 BazarCall IOCs

Jun 15th, 2021
18,129
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.21 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZARCALL / BAZARLOADER
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. FWD: Automated premium subscription update notice VC7############## 🤗
  7. Your free trial version ends soon, VC7############## . Your premium plan will immediately renew itself.
  8. Your free trial version will expire soon, VC7############## . Your membership will immediately re-new itself.
  9. Your trial offer will expire really soon, VC7############## . Your premium plan will instantly renew itself.
  10. Your trial offer will expire soon, VC7############## . Your premium will immediately renew itself.
  11.  
  12. LURE PHONE NUMBER
  13. +1 213 401 2706
  14.  
  15. MALDOC LANDING PAGE URLS
  16. https://zonerphotos.com/
  17.  
  18. MALDOC DOWNLOAD URLS
  19. https://zonerphotos.com/cancel.php
  20.  
  21. MALDOC (XLSB) FILE HASHES
  22. cancel_sub_VC7##############.xlsb
  23. 94e15e803bee24cb13ed11498d3abb9d
  24.  
  25. BAZARLOADER PAYLOAD DOWNLOAD URLs
  26. First call is to:
  27. http://195.123.222.109/
  28.  
  29. which does a 302 redirect to:
  30. http://th4c910ma9puls.xyz/xe1t23ym0s.php
  31.  
  32. BAZARLOADER FILE HASHES
  33. gz5oOdsKu.dll
  34. a4d96695e894dd22feb7e3e3b0dd6887
  35.  
  36. BAZARLOADER C2
  37. https://172.83.155.161/corp/sentinel
Advertisement
Add Comment
Please, Sign In to add comment