ExecuteMalware

2021-04-27 BazarCall IOCs

Apr 27th, 2021
17,143
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.04 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDERS OBSERVED
  4.  
  5. SUBJECTS OBSERVED
  6. Congratulations! Your order has been approved.
  7. Congratulations! Your order was approved.
  8. Well done! Your order has been approved.
  9. Your order Z0012############ has been confirmed. Address delivery will not take long!
  10.  
  11. LURE PHONE NUMBER
  12. 1 323 540 5822
  13.  
  14. MALDOC LANDING PAGE URLS
  15. https://prinpro.us
  16. https://printequip.us
  17. https://printools.us
  18. https://proprin.us
  19. https://profiprint.us
  20.  
  21. MALDOC DOWNLOAD URLS
  22. https://prinpro.us/cancel.php
  23. https://printequip.us/cancel.php
  24.  
  25. https://printools.us/cancel.php
  26. 302 to:
  27. https://printools.us/suspicious-traffic
  28.  
  29. MALDOC (XLSB) FILE HASHES
  30. order_Z0012112202927225.xlsb
  31. ae7ee17fe1beca77792942d4401c3f50
  32.  
  33. ADDITIONAL/CAMPO LOADER FILES
  34. 28222.dr1
  35. 547a4e8b1b3bf3359785479e768fa246
  36.  
  37. 28222.dr2
  38. 547a4e8b1b3bf3359785479e768fa246
  39.  
  40. 28222.dr3
  41. fe696977648eed8a2b0ab9dcdd70aca2
  42.  
  43. CAMPO LOADER PAYLOAD DOWNLOAD URLS
  44. http://lie3.xyz/campo/li/e3
Advertisement
Add Comment
Please, Sign In to add comment