ExecuteMalware

2021-03-22 Bazar IOCs

Mar 22nd, 2021
4,692
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.66 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZAR
  2.  
  3. SUBJECTS OBSERVED
  4. APM Terminals -- Payment receipt # 54342747WW
  5.  
  6. SENDERS OBSERVED
  7.  
  8. MALDOC FILE HASHES
  9. form_1348168160_1927608554.xls
  10. f850ae7b2b87271f7e2b009a84734122
  11.  
  12. BAZAR PAYLOAD DOWNLOAD
  13. http://ravepsychiatry.com/t/optonline.php
  14. http://ravepsychiatry.com/t/sore.php
  15.  
  16. BAZAR PAYLOAD FILE HASHES
  17. optonline.dll
  18. 2c4ba65ebe45a97b6e43a971c6ad580b
  19.  
  20. sore.dll
  21. 4aa61251226a51e9bdf40487265ab8be
  22.  
  23. BAZAR C2
  24. None
  25.  
  26. SUPPORTING EVIDENCE
  27. https://www.virustotal.com/gui/file/407efed8e868c0a3e8ef9dfbce26b48bdcd03b80dabdb39fadc4b16094e89bd1/details
  28. https://app.any.run/tasks/31db7cea-fcf7-4bef-ba11-d3ba13fed1e6/
  29.  
Advertisement
Add Comment
Please, Sign In to add comment