MalwareBreakdown

07/08/2020: ZLoader Campaign IOCs

Jul 8th, 2020
13,295
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.67 KB | None | 0 0
  1. https://twitter.com/DynamicAnalysis/status/1280892126428114944
  2.  
  3. #ZLoader #malspam from today.
  4.  
  5. Downloader URLs:
  6. https://dayton.store/wp-index.php
  7. https://karen.store/wp-index.php
  8. https://ticformjunclenneo.tk/wp-index.php
  9. https://quechardojecde.tk/wp-index.php
  10.  
  11. C2s:
  12. https://m.ultimatefitnessholiday.com/wp-parsing.php
  13. https://netinup.it/wp-parsing.php
  14. https://oneolimpio.tech/wp-parsing.php
  15. https://adgersandviho.cf/wp-parsing.php
  16. https://paraben-sticks.com/wp-parsing.php
  17. https://tralsiwheepegangcomp.tk/wp-parsing.php
  18. https://parceirosvendaativa.club/wp-parsing.php
  19.  
  20. XLS sample:
  21. https://bazaar.abuse.ch/sample/1615c46ae8e9b2f243ed4e124edffeea4cd452fd5a2ad92b496260e1c963ae86/
  22.  
  23. DLL sample:
  24. https://urlhaus.abuse.ch/url/408935/
  25.  
  26. More #ZLoader from today:
  27.  
  28. Downloader URLs:
  29. http://anatoliadrilling.com/wp-keys.php
  30. http://charlesengineering.in/wp-keys.php
  31. http://dcws-ev.com/wp-keys.php
  32. http://doorbhai.com/wp-keys.php
  33.  
  34. C2s:
  35. https://rdaprint.in/wp-parsing.php
  36. https://vishweshwarastrology.com/wp-parsing.php
  37. https://statpasapipag.tk/wp-parsing.php
  38. https://www.netinup.it/wp-parsing.php
  39. https://www.oneolimpio.tech/wp-parsing.php
  40. https://hanskingrypgirigolf.ml/wp-parsing.php
  41.  
  42. XLS sample:
  43. https://app.any.run/tasks/12edc796-2a56-471c-bb56-84c65f47202f
  44.  
  45. DLL sample:
  46. https://app.any.run/tasks/9ecdfe88-dcb9-4e16-a1e6-62868c37b904
Add Comment
Please, Sign In to add comment