Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT IDENTIFICATION: BAZARCALL
- NOTES:
- I did not get a payload after the initial /campo/ url.
- I saw failed DNS queries to 5 of the older web site domains
- I did receive a few .exe files by manually visiting some newly found domains.
- DNS QUERIES TO:
- imerservice.net
- merservice.org
- icartservice.org
- imedservice.org
- icartservice.app
- All returned "Server Failure"
- SENDER EMAILS
- icart@icart.com
- inf@icartservice.com
- info@icartservice.com
- it@icartservice.com
- service@icartservice.com
- site@icartservice.com
- SUBJECTS
- Do you want to extend your free period 032911349855?
- Do you want to extend your free period 032971082739?
- Do you want to extend your free period 032992342492?
- Do you want to extend your free trial 032914360334?
- Do you want to extend your free trial 032929965053?
- Do you want to extend your free trial 032960551023?
- Thank you for using your free period 032911349855. Time to move on!
- Thank you for using your free period 032959551266. Time to move on!
- Thank you for using your free trial 032928460385. Time to move on!
- Thank you for using your free trial 032942918497. Time to move on!
- Thank you for using your free trial 032967802762. Time to move on!
- Thank you for using your free trial 032983352838. Time to move on!
- Your free period 032924713704 is almost over!
- Your free period 032928460385 is about to be over!
- Your free period 032931754105 is going to end!
- Your free period 032937843104 is about to end!
- Your free period 032942918497 is going to end!
- Your free period 032943423209 is going to end!
- Your free period 032945874491 is going to end!
- Your free period 032959316990 is about to be over!
- Your free period 032971082739 is about to end!
- Your free period 032992342492 is about to be over!
- Your free trial 032976172338 is going to end!
- Your free trial 032990118057 is going to end!
- Your free trial KMR59157203 is going to end!
- Your free trial period 032901433429 is almost over!
- Your free trial period 032926747691 is almost over!
- Your free trial period 032991478849 is almost over!
- Your free trial period 032995250960 is almost over!
- LURE PHONE NUMBER
- Not available
- MALDOC DOWNLOAD URLS
- https://buyimers.us/unsubscribe.html
- https://geticart.us/unsubscribe.html
- https://getmers.us/unsubscribe.html
- https://gobcs.us/unsubscribe.html
- https://goimed.us/unsubscribe.html
- buyimers.us
- geticart.us
- getmers.us
- gobcs.us
- goimed.us
- MALDOC FILE HASHES
- 01e837d28214d80ebd2b296c396b44ed
- 130893af30fcf98c0aa40aa046830aab
- 53a5ee3ae476003221d1c8dbb66f9002
- 53abb39593ba0a09f533b7c3be943095
- 86304059c0a7afb48f2cf6adde54ba0f
- 89ed9bbd3cc6ce767bdf1367ee7286d4
- b7e521668beb98038c2cff9c6da9caa3
- c73b781aeefa1ead369ed213578eba80
- d27359706233d20207bc02e0a100bd42
- dc2169f92205f6ed5e66fd475bb86b04
- e6b545518ac11fc9b76182ce9ad120fa
- PAYLOAD DOWNLOAD URLS
- http://veso2.xyz/campo/r/r1
- ADDITIONAL PAYLOAD DOMAINS
- gobcss.xyz
- buymers.xyz
- golmed.xyz
- gtmers.xyz
- igetcart.xyz
- q1x250gr0ln2icfa.xyz
- q2jac2w68xl5r2z.xyz
- q3w52umx3kaa3u.xyz
- ADDITONAL PAYLOAD FILE HASHES
- 1617039449.exe
- 18a727ec5e32a9d13250578e93b3cc47
- 1617039629.exe
- 2caa8c254710493f9d82331899d0bf31
- 1617039451.exe
- 6535026f586eadf50f8f2d3dc8bab785
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement