Advertisement
ExecuteMalware

2021-03-31 BazarCall IOCs

Mar 31st, 2021
18,925
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.20 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZAR CALL / BAZAR LOADER
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Do you want to extend your free period ###########?
  7. Free trial period for ############ will end in 3 days
  8. Free trial period for ############ will end in three days
  9. Thank you for using your free period ###########. Time to move on!
  10. Your free period ########### is about to be over!
  11. Your free period ########### is about to end!
  12. Your free period ########### is almost over!
  13. Your free period ########### is going to end!
  14. Your free trial ########### is about to end!
  15. Your free trial ########### is going to end!
  16. Your free trial period ########### is almost finished
  17. Your free trial period ########### is almost over!
  18.  
  19. LURE PHONE NUMBER
  20. 1 (213) 401 9021
  21. 1 (657) 220 1695
  22.  
  23. MALDOC DOWNLOAD URLS
  24. getmers.us
  25. https://gtmers.xyz/unsubscribe.html
  26. Result = 404
  27.  
  28. gobcs.us
  29. https://gobcss.xyz/unsubscribe.html
  30. Result = .xlsb
  31.  
  32. geticart.us
  33. https://igetcart.xyz/unsubscribe.html
  34. Result = .xlsb
  35.  
  36. https://goimed.us/
  37. https://goimed.us/unsubscribe.html
  38. Result = 404
  39.  
  40. buyimers.us
  41. https://buymers.xyz/unsubscribe.html
  42. Result = .xlsb
  43.  
  44. getmers.us
  45. gobcs.us
  46. geticart.us
  47. goimed.us
  48. buyimers.us
  49.  
  50. MALDOC (XLSB) FILE HASHES
  51. 562f79b140956396a2565ceb517bd4c3
  52. 5fd381f999d95ce87bd371855c12b918
  53. 61f088075376c04815f611dc0a60882e
  54. 687b33fe6d8101cd86f27754a04b38e9
  55. aca3073d2fa419834bd1998806103dca
  56. fe9b3d6f7c68e6d2ac10aec454051267
  57.  
  58. PAYLOAD DOWNLOAD URLS
  59. http://about2.xyz/campo/a/a1
  60. http://about2.xyz/uploads/files/rl103.exe
  61.  
  62. PAYLOAD FILE HASHES
  63. rl103.exe
  64. 4bf479d0fcb081c8ab68c41d848d593d
  65.  
  66. renamed to:
  67. fjlq.exe
  68. 4bf479d0fcb081c8ab68c41d848d593d
  69.  
  70. ADDITIONAL TRAFFIC
  71. https://18.223.206.249
  72. https://3.86.82.29
  73.  
  74. ADDITIONAL FILE HASHES FROM PAYLOAD DOMAIN
  75. yer5e.exe
  76. fae1cf371d316ddd6918efda8b993f72
  77.  
  78. rety5r2.exe
  79. 88df8e94cd1738d631974c9aff361c8f
  80.  
  81. ret5er.exe
  82. 68defeb5cbf90fac11e4db64d2e39ab5
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement