Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL / BAZARLOADER
- SENDERS OBSERVED
- mrkd4lif@eatel.net
- SUBJECTS OBSERVED
- Trial stage is now over! Your account #M027202########## is going to be automatically moved to premium plan!
- LURE PHONE NUMBER
- 1 313 725 9061
- MALDOC LANDING PAGE URLS
- https://urbancinema.net/
- https://urbancinema.net/FAQ
- https://urbancinema.net/subscribe
- MALDOC DOWNLOAD URLS
- https://urbancinema.net/cancel.php
- MALDOC (XLSB) FILE HASHES
- cancel_sub_M0272029458353238.xlsb
- d132745d903704af5360b31fadbb7025
- Evening run:
- cancel_sub_M0272029458353238.xlsb
- 7ce50dd5f5f82e6c0c8d236039c57b5c
- CAMPO LOADER DOWNLOAD URLS
- http://noise1.xyz/campo/n/s
- http://noise1.xyz/campo/n/o
- CAMPO LOADER FILES
- 6123.xlsb
- 08553ef3887f32d0141463ccab705f03
- 6123.xsd
- 08553ef3887f32d0141463ccab705f03
- 6123.xdo
- d20868a33c24969ea9802cae5ebce0db
- BAZARLOADER PAYLOAD FILE HASH
- http://noise1.xyz/uploads/files/rest.exe
- BAZARLOADER FILE HASH
- rest.exe
- 96764a0a62e66a147a3d4db0e59a6e34
- renamed to:
- 6087.exe
- Later run, renamed to:
- euygj.exe
- BAZARLOADER C2s
- https://18.237.242.195/g1_262/bt_64_g1_262
- SUPPORTING EVIDENCE
- https://urlhaus.abuse.ch/url/1197419/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement