Advertisement
ExecuteMalware

2020-12-10 Bazar IOCs

Dec 10th, 2020
3,448
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.96 KB | None | 0 0
  1. THREAT ATTRIBUTION: BAZAR
  2.  
  3. SUBJECTS OBSERVED
  4. RE: <Company Name> termination list
  5. RE: <Company Name>: employee bonuses
  6.  
  7. SENDERS OBSERVED
  8. catrina.suldon@tycoglobalfinancialsolutions.com
  9. Jacqueline.Harris@siliconpeak.net
  10. Andrea.Evans@zippd.com
  11. TIFFANIE.LOVETT@siliconpeak.net
  12.  
  13. BAZAR PAYLOAD FILE HASHES
  14. PreviewDoc.exe
  15. 532524ec1e7a51b51f948fdc79bd0f83
  16.  
  17. DIGITAL SIGNATURE
  18. OOO Inversum
  19.  
  20. LANDING PAGE URLS
  21. https://docs.google.com/document/d/e/2PACX-1vRbIITKRwwDZi-IGGLJbZw9xlJyWGGiHKhifh6h2pZrujOQIpi792gliqaif2i_yYs91luHfJWOBgul/pub
  22. https://docs.google.com/document/d/e/2PACX-1vQ47uql5TBmOkBRUZTMZBQpyaFKle50tquSGz9dilBBehe23YLqU2T6UszPtJ4qrICJnRlBCYRKN6jL/pub
  23.  
  24. PAYLOAD DOWNLOAD URLS
  25. https://www.google.com/url?q=https://drive.google.com/uc?export%3Ddownload%26id%3D1TjgOQjFKqGdRW3A0GjfHCgrXu1scBx5A&sa=D&ust=1607627596249000&usg=AOvVaw3zj3kOwq3dDu2CrlfCocU0
  26.  
  27. BAZAR C2 (Possible C2s)
  28. https://ecosmartdetaillng.com
  29. 51.77.94.237
  30.  
  31. https://chukysdetall.com.com
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement