ExecuteMalware

2021-04-01 BazarCall IOCs

Apr 1st, 2021
17,046
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.61 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free trial ############?
  7. Free period for ############ is almost over.
  8. Your free period ############ is about to end!
  9. Your free period ############ is almost over!
  10. Your free period ############ is about to end!
  11. Your free period ############ is almost over!
  12. Your free trial ############ is about to end!
  13. Your free trial period ############ is almost over!
  14.  
  15. LURE PHONE NUMBER
  16. 1 (901) 584 0490
  17. 1 (213) 401 9021
  18.  
  19. MALDOC LANDING PAGE DOMAINS
  20. buyimers.us
  21. geticart.us
  22. getmers.us
  23. gobcs.us
  24. goimed.us
  25.  
  26. MALDOC DOWNLOAD URLS
  27. https://getmerss.xyz/unsubscribe.html
  28. https://goibcs.xyz/unsubscribe.html
  29. https://getlcart.xyz/unsubscribe.html
  30. https://igomed.xyz/unsubscribe.html
  31. https://buylmers.xyz/unsubscribe.html
  32.  
  33. buylmers.xyz
  34. geticart.xyz
  35. getmerss.xyz
  36. goibcs.xyz
  37. igomed.xyz
  38.  
  39. MALDOC (XLSB) FILE HASHES
  40. 11cc65a8c350b91de6ea341eaeefa3de
  41. 8255c1e595a30ae5cb4f047423043c13
  42. 91edbc51a4e25ca3354a82d229828c87
  43. 9cb09ce52055479aae79ba3c6a3d21fd
  44. f5d9155a56cdbdf8a421e5bf106915b2
  45.  
  46. PAYLOAD DOWNLOAD URLS
  47. http://board3.xyz/campo/d/d1
  48. http://board3.xyz/uploads/files/rldr.10.4.exe
  49.  
  50. PAYLOAD FILE HASHES
  51. rldr.10.4.exe
  52. 81e6dcf2510ffc2400743e912448013f
  53.  
  54. renamed to:
  55. MRXBA3F.exe
  56. 81e6dcf2510ffc2400743e912448013f
  57.  
  58. ADDITIONAL TRAFFIC
  59. mRXBA3F.exe calls out to:
  60. https://34.212.193.150
  61.  
  62. ADDITIONAL FILE HASHES FROM PAYLOAD DOMAIN
  63. r104.exe
  64. d2749c21fa8671e75cd147380ff110e0
  65.  
  66. ret4.exe
  67. 9b224a8a1e6e5897e47fee0eb1e21766
  68.  
  69. 1616183460
  70. 91ee2afefdf066eae3aead061a8075ed
Advertisement
Add Comment
Please, Sign In to add comment