ExecuteMalware

2021-04-06 BazarCall IOCs

Apr 6th, 2021
16,878
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.10 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. SENDER EMAILS
  4.  
  5. SUBJECTS
  6. Free trial period for ############# comes to the end in three days
  7. Your free trial ############ is about to end!
  8. Thank you for using your free trial ############. Time to move on!
  9.  
  10. LURE PHONE NUMBER
  11. +1 (209) 554 3767
  12.  
  13. MALDOC LANDING PAGE URLS
  14. https://bookpoint.us
  15. https://bookspoint.us
  16. https://pointbook.us
  17. https://pointbooks.us
  18. https://subsbookpoint.us
  19.  
  20. MALDOC DOWNLOAD URLS
  21. https://bokpoint.xyz/unsubscribe
  22. https://bokspoint.xyz/unsubscribe
  23. https://pointbok.xyz/unsubscribe
  24. https://pointboks.xyz/unsubscribe
  25.  
  26. MALDOC (XLSB) FILE HASHES
  27. 759b9d6d287e240dc4a9a1564043e4d5
  28. 6740ff5b4d99d21c8ae34f2bf5b4cd71
  29. 4de36ea29963104bac17ee17176b0c6b
  30. 06ffd88bb900090461f59cdabed2d252
  31. 04023332ae2160489d04446a4f539fc7
  32.  
  33. PAYLOAD DOWNLOAD URLS
  34. Unknown
  35.  
  36. PAYLOAD FILE HASHES
  37. Unknown
  38.  
  39. ADDITIONAL FILE HASHES FROM PAYLOAD DOMAIN
  40. 569390.ui
  41. c7a8147760434d6eca16d8e27dce2bcf
  42.  
  43. 569390.xlsb
  44. 260a8af59a31a82aa8f999760b8fcb66
  45.  
  46. 569390.pdi
  47. 260a8af59a31a82aa8f999760b8fcb66
  48.  
Advertisement
Add Comment
Please, Sign In to add comment