ExecuteMalware

2021-06-14 BazarCall IOCs

Jun 14th, 2021
16,703
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.81 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL / BAZARLOADER
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. Your free trial version ends very soon, VCP##############. Your membership will instantly renew itself.
  7.  
  8. LURE PHONE NUMBER
  9. UNKNOWN
  10.  
  11. MALDOC LANDING PAGE URLS
  12. https://vcophoto.us
  13.  
  14. MALDOC DOWNLOAD URLS
  15. https://vcophoto.us/cancel.php
  16.  
  17. MALDOC (XLSB) FILE HASHES
  18. cancel_sub_VCP##############.xlsb
  19. 1e9570436a3ad07088cdc6c2293ba4f2
  20.  
  21. BAZARLOADER PAYLOAD DOWNLOAD URLs
  22. First call is to:
  23. http://5.34.179.24
  24.  
  25. which does a 302 redirect to:
  26. http://f88p8ky5brej.xyz/xe1t23ym0s.php
  27.  
  28. BAZARLOADER FILE HASHES
  29. DqYuH.dll
  30. 806a2df1a437a063b7e167acca5c7b12
  31.  
  32. BAZARLOADER C2
  33. https://54.67.116.246/api/outgoing/connection
  34. https://34.209.29.159/army/hangar
  35.  
  36. SUPPORTING EVIDENCE
  37. https://tria.ge/210614-ba8qveeh8e
Advertisement
Add Comment
Please, Sign In to add comment