ExecuteMalware

2021-07-21 BazarLoader IOCs

Jul 21st, 2021
15,927
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.99 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Contact Submission
  5.  
  6. SENDERS OBSERVED
  7.  
  8. EMAIL BODY
  9. name: Christina
  10. message: Hello there! My name is Christina. Your website or a website
  11. that your company hosts is violating the copyright protected images
  12. owned by myself. Check out this document with the hyperlinks to my
  13. images you used at www.<redacted>.com and my previous publications to find
  14. the evidence of my copyrights. Download it right now and check this
  15. out for yourself:
  16. https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-dk3kvbbqk2.html?alt=media&token=e9774a52-79aa-4b10-9863-67a63a9e1087&l=235887401976653861
  17.  
  18. I really believe you have intentionally violated my legal rights under
  19. 17 USC Sec. 101 et seq. and could possibly be liable for statutory
  20. damages as high as $150,000 as set-forth in Section 504 (c)(2) of the
  21. Digital Millennium Copyright Act (DMCA) therein. This letter is
  22. official notification. I demand the removal of the infringing
  23. materials described above. Take note as a service provider, the Dmca
  24. requires you, to remove and terminate access to the infringing content
  25. upon receipt of this particular notification letter. In case you don't
  26. stop the use of the previously mentioned infringing materials a
  27. lawsuit can be started against you. I do have a good self-belief that
  28. use of the copyrighted materials described above as presumably
  29. infringing is not permitted by the legal copyright owner, its legal
  30. agent, as well as law. I declare, under consequence of perjury, that
  31. the information in this letter is accurate and that I am currently the
  32. copyright proprietor or am authorized to act on behalf of the owner of
  33. an exclusive right that is allegedly infringed. Regards, Christina
  34. Morris 07/21/2021
  35.  
  36. MALDOC DOWNLOAD URLS
  37. https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-dk3kvbbqk2.html?alt=media&token=e9774a52-79aa-4b10-9863-67a63a9e1087&l=235887401976653861
  38.  
  39. https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-dk3kvbbqk2.html?alt=media&token=e9774a52-79aa-4b10-9863-67a63a9e1087&data=04258728259875443
  40.  
  41. https://drive.google.com/uc?export=download&id=1WsuhRIiE37T19uuQkg_0z8lAarKmZyD1
  42. https://drive.google.com/uc?export=download&id=18XdoojFcWJbV_sFG3jGeusXpExG0VS2C
  43.  
  44. MALDOC FILE NAMES
  45. Stolen Images Evidence.zip
  46. Stolen Images Evidence.js
  47.  
  48. MALDOC FILE HASHES
  49. Stolen Images Evidence.zip
  50. 372465bc30e35f6fd15a4b12a51ef988
  51.  
  52. Stolen Images Evidence.js
  53. c6545c4a32834f0026b9d17ab3e9425e
  54.  
  55. BAZARLOADER PAYLOAD DOWNLOAD URLS
  56. http://menoiras.space/222g100/index.php
  57. http://menoiras.space/222g100/main.php
  58.  
  59. BAZARLOADER PAYLOAD FILE HASHES
  60. yeWvzid.dat (it's a .dll)
  61. 7441e18b28b78a1c9fb5323099ea1510
  62.  
  63. BAZARLOADER C2
  64. https://3.223.192.20/union/low_item
  65.  
  66. DNS TRAFFIC (None resolved)
  67. greencloud46a.bazar
  68. whitestorm9p.bazar
  69. yellowdownpour81.bazar
  70.  
  71. SUPPORTING EVIDENCE
  72. https://app.any.run/tasks/44470730-363d-45a0-8ec3-291e3ee0cd93/
  73.  
Advertisement
Add Comment
Please, Sign In to add comment