ExecuteMalware

2021-03-29 BazarCall IOCs

Mar 29th, 2021
16,831
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.14 KB | None | 0 0
  1. THREAT IDENTIFICATION: BAZARCALL
  2.  
  3. NOTES:
  4. I did not get a payload after the initial /campo/ url.
  5. I saw failed DNS queries to 5 of the older web site domains
  6. I did receive a few .exe files by manually visiting some newly found domains.
  7.  
  8. DNS QUERIES TO:
  9. imerservice.net
  10. merservice.org
  11. icartservice.org
  12. imedservice.org
  13. icartservice.app
  14.  
  15. All returned "Server Failure"
  16.  
  17. SENDER EMAILS
  18.  
  19. SUBJECTS
  20. Do you want to extend your free period 032911349855?
  21. Do you want to extend your free period 032971082739?
  22. Do you want to extend your free period 032992342492?
  23. Do you want to extend your free trial 032914360334?
  24. Do you want to extend your free trial 032929965053?
  25. Do you want to extend your free trial 032960551023?
  26. Thank you for using your free period 032911349855. Time to move on!
  27. Thank you for using your free period 032959551266. Time to move on!
  28. Thank you for using your free trial 032928460385. Time to move on!
  29. Thank you for using your free trial 032942918497. Time to move on!
  30. Thank you for using your free trial 032967802762. Time to move on!
  31. Thank you for using your free trial 032983352838. Time to move on!
  32. Your free period 032924713704 is almost over!
  33. Your free period 032928460385 is about to be over!
  34. Your free period 032931754105 is going to end!
  35. Your free period 032937843104 is about to end!
  36. Your free period 032942918497 is going to end!
  37. Your free period 032943423209 is going to end!
  38. Your free period 032945874491 is going to end!
  39. Your free period 032959316990 is about to be over!
  40. Your free period 032971082739 is about to end!
  41. Your free period 032992342492 is about to be over!
  42. Your free trial 032976172338 is going to end!
  43. Your free trial 032990118057 is going to end!
  44. Your free trial KMR59157203 is going to end!
  45. Your free trial period 032901433429 is almost over!
  46. Your free trial period 032926747691 is almost over!
  47. Your free trial period 032991478849 is almost over!
  48. Your free trial period 032995250960 is almost over!
  49.  
  50. LURE PHONE NUMBER
  51. Not available
  52.  
  53. MALDOC DOWNLOAD URLS
  54. https://buyimers.us/unsubscribe.html
  55. https://geticart.us/unsubscribe.html
  56. https://getmers.us/unsubscribe.html
  57. https://gobcs.us/unsubscribe.html
  58. https://goimed.us/unsubscribe.html
  59.  
  60. buyimers.us
  61. geticart.us
  62. getmers.us
  63. gobcs.us
  64. goimed.us
  65.  
  66. MALDOC FILE HASHES
  67. 01e837d28214d80ebd2b296c396b44ed
  68. 130893af30fcf98c0aa40aa046830aab
  69. 53a5ee3ae476003221d1c8dbb66f9002
  70. 53abb39593ba0a09f533b7c3be943095
  71. 86304059c0a7afb48f2cf6adde54ba0f
  72. 89ed9bbd3cc6ce767bdf1367ee7286d4
  73. b7e521668beb98038c2cff9c6da9caa3
  74. c73b781aeefa1ead369ed213578eba80
  75. d27359706233d20207bc02e0a100bd42
  76. dc2169f92205f6ed5e66fd475bb86b04
  77. e6b545518ac11fc9b76182ce9ad120fa
  78.  
  79. PAYLOAD DOWNLOAD URLS
  80. http://veso2.xyz/campo/r/r1
  81.  
  82.  
  83. ADDITIONAL PAYLOAD DOMAINS
  84. gobcss.xyz
  85. buymers.xyz
  86. golmed.xyz
  87. gtmers.xyz
  88. igetcart.xyz
  89. q1x250gr0ln2icfa.xyz
  90. q2jac2w68xl5r2z.xyz
  91. q3w52umx3kaa3u.xyz
  92.  
  93. ADDITONAL PAYLOAD FILE HASHES
  94. 1617039449.exe
  95. 18a727ec5e32a9d13250578e93b3cc47
  96.  
  97. 1617039629.exe
  98. 2caa8c254710493f9d82331899d0bf31
  99.  
  100. 1617039451.exe
  101. 6535026f586eadf50f8f2d3dc8bab785
  102.  
  103.  
Advertisement
Add Comment
Please, Sign In to add comment