ExecuteMalware

2021-05-05 BazarCall IOCs

May 5th, 2021
17,420
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.17 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL / BAZARLOADER
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. Trial stage is now over! Your account #M027202########## is going to be automatically moved to premium plan!
  7.  
  8. LURE PHONE NUMBER
  9. 1 313 725 9061
  10.  
  11. MALDOC LANDING PAGE URLS
  12. https://urbancinema.net/
  13. https://urbancinema.net/FAQ
  14. https://urbancinema.net/subscribe
  15.  
  16. MALDOC DOWNLOAD URLS
  17. https://urbancinema.net/cancel.php
  18.  
  19. MALDOC (XLSB) FILE HASHES
  20. cancel_sub_M0272029458353238.xlsb
  21. d132745d903704af5360b31fadbb7025
  22.  
  23. Evening run:
  24. cancel_sub_M0272029458353238.xlsb
  25. 7ce50dd5f5f82e6c0c8d236039c57b5c
  26.  
  27. CAMPO LOADER DOWNLOAD URLS
  28. http://noise1.xyz/campo/n/s
  29. http://noise1.xyz/campo/n/o
  30.  
  31. CAMPO LOADER FILES
  32. 6123.xlsb
  33. 08553ef3887f32d0141463ccab705f03
  34.  
  35. 6123.xsd
  36. 08553ef3887f32d0141463ccab705f03
  37.  
  38. 6123.xdo
  39. d20868a33c24969ea9802cae5ebce0db
  40.  
  41. BAZARLOADER PAYLOAD FILE HASH
  42. http://noise1.xyz/uploads/files/rest.exe
  43.  
  44. BAZARLOADER FILE HASH
  45. rest.exe
  46. 96764a0a62e66a147a3d4db0e59a6e34
  47.  
  48. renamed to:
  49. 6087.exe
  50.  
  51. Later run, renamed to:
  52. euygj.exe
  53.  
  54. BAZARLOADER C2s
  55. https://18.237.242.195/g1_262/bt_64_g1_262
  56.  
  57. SUPPORTING EVIDENCE
  58. https://urlhaus.abuse.ch/url/1197419/
Advertisement
Add Comment
Please, Sign In to add comment