Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL
- SENDER EMAILS
- 3@servicei.com
- info@icartservice.com
- support@myicart.com
- usa@servicei.com
- SUBJECTS
- Do you want to extend your free trial ############?
- Free period for ############ is almost over.
- Your free period ############ is about to end!
- Your free period ############ is almost over!
- Your free period ############ is about to end!
- Your free period ############ is almost over!
- Your free trial ############ is about to end!
- Your free trial period ############ is almost over!
- LURE PHONE NUMBER
- 1 (901) 584 0490
- 1 (213) 401 9021
- MALDOC LANDING PAGE DOMAINS
- buyimers.us
- geticart.us
- getmers.us
- gobcs.us
- goimed.us
- MALDOC DOWNLOAD URLS
- https://getmerss.xyz/unsubscribe.html
- https://goibcs.xyz/unsubscribe.html
- https://getlcart.xyz/unsubscribe.html
- https://igomed.xyz/unsubscribe.html
- https://buylmers.xyz/unsubscribe.html
- buylmers.xyz
- geticart.xyz
- getmerss.xyz
- goibcs.xyz
- igomed.xyz
- MALDOC (XLSB) FILE HASHES
- 11cc65a8c350b91de6ea341eaeefa3de
- 8255c1e595a30ae5cb4f047423043c13
- 91edbc51a4e25ca3354a82d229828c87
- 9cb09ce52055479aae79ba3c6a3d21fd
- f5d9155a56cdbdf8a421e5bf106915b2
- PAYLOAD DOWNLOAD URLS
- http://board3.xyz/campo/d/d1
- http://board3.xyz/uploads/files/rldr.10.4.exe
- PAYLOAD FILE HASHES
- rldr.10.4.exe
- 81e6dcf2510ffc2400743e912448013f
- renamed to:
- MRXBA3F.exe
- 81e6dcf2510ffc2400743e912448013f
- ADDITIONAL TRAFFIC
- mRXBA3F.exe calls out to:
- https://34.212.193.150
- ADDITIONAL FILE HASHES FROM PAYLOAD DOMAIN
- r104.exe
- d2749c21fa8671e75cd147380ff110e0
- ret4.exe
- 9b224a8a1e6e5897e47fee0eb1e21766
- 1616183460
- 91ee2afefdf066eae3aead061a8075ed
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement