Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: BAZARLOADER
- SUBJECTS OBSERVED
- Contact Submission
- SENDERS OBSERVED
- Christina <[email protected]>
- EMAIL BODY
- name: Donna
- email: [email protected]
- message: Hello! My name is Donna. Your website or a website that your
- organization hosts is infringing on a copyright protected images owned
- by me personally. Check out this official document with the hyperlinks
- to my images you used at www.<redacted>.com and my previous publications
- to obtain the evidence of my copyrights. Download it now and check
- this out for yourself:
- https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-3dk3nvbv4ju3n.html?alt=media&token=0471b204-69d8-4a6c-914a-31a622163a92&l=157298857286671654
- I believe that you intentionally violated my rights under 17 U.S.C.
- Section 101 et seq. and could possibly be liable for statutory damages
- of up to $120,000 as set-forth in Sec. 504 (c) (2) of the Digital
- millennium copyright act (DMCA) therein. This letter is official
- notice. I demand the removal of the infringing materials described
- above. Please take note as a service provider, the DMCA demands you,
- to remove and/or terminate access to the infringing materials upon
- receipt of this letter. In case you don't cease the use of the
- previously mentioned infringing content a legal action will likely be
- initiated against you. I do have a strong belief that use of the
- copyrighted materials mentioned above as presumably infringing is not
- permitted by the copyright owner, its agent, or the legislation. I
- declare, under penalty of perjury, that the information in this
- message is correct and that I am the copyright proprietor or am
- authorized to act on behalf of the owner of an exclusive and legal
- right that is presumably violated. Regards, Donna Arnold 07/30/2021
- MALDOC DOWNLOAD URLS
- https://firebasestorage.googleapis.com/v0/b/files-d6e6c.appspot.com/o/download-3dk3nvbv4ju3n.html?alt=media&token=0471b204-69d8-4a6c-914a-31a622163a92&l=157298857286671654
- MALDOC FILE NAMES
- Stolen Images Evidence.zip
- 2200c6bfbc4489effc47106b99f070f5
- MALDOC FILE HASHES
- Stolen Images Evidence.js
- 989573ea161dfc6b6a9246c4811a0207
- BAZARLOADER PAYLOAD DOWNLOAD URLS
- http://moigoran.space/222g100/index.php
- http://moigoran.space/222g100/main.php
- BAZARLOADER PAYLOAD FILE HASHES
- (They're both .dll files)
- JGkFDlBp.dat
- cef50486fe3ecb76d2f85c711fa58d62
- Another run, it was this:
- ScCfJb.dat
- fb4b64bc12dd252a80eb28706bd33596
- BAZARLOADER C2
- https://18.237.101.6/insect/bee
- https://18.144.168.38/insect/bee
- PDB PATH FOUND IN MEMORY
- (from lsass.exe process)
- D:\projects\source\repos\7\bd7 v2\Bin\x64\Release_nologs\bd7_x64_release_nologs.pdb
Advertisement
Add Comment
Please, Sign In to add comment