Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: ZLOADER
- SUBJECTS OBSERVED
- Additional information about Receipt # 2757
- Agreement ID 9804 info
- Information regarding invoice 9997
- This is your Customer Invoice -# 2587
- SENDERS OBSERVED
- axelbs713@aol[.]com
- kevincarter689@aol[.]com
- kremilek28@aol[.]com
- nevestamg_80@aol[.]com
- EXCEL FILE NAMES
- st[.]9804[.]xls
- Payment-2587[.]xls
- Det[.]2757[.]xls
- EXCEL FILE HASHES
- 1e110417716b6e8d2688e2686e5d0687
- 20b29478852c93bbc2c3e19bec66af56
- e2314005d83eb68293b1cd932f0e6e11
- ZLOADER PAYLOAD HASHES
- N/A
- ZLOADER PAYLOAD URLs
- hxxps://albeeah[.]co/zg5ndr[.]php
- hxxps://digidraft[.]in/ve5hpk[.]php
- hxxps://htrackbrand[.]com/h0g6g6[.]php
- hxxps://htrackbrand[.]com/oltxgw[.]php
- hxxps://icapturefilms[.]com/jo4xyy[.]php
- hxxps://iptvipstore[.]com/a070ru[.]php
- hxxps://mail[.]htrackbrand[.]com/6bfcaf[.]php
- hxxps://recrugenie[.]cm/cqvlp9[.]php
- albeeah[.]co
- htrackbrand[.]com
- mail[.]htrackbrand[.]com
- recrugenie[.]cm
- digidraft[.]in
- htrackbrand[.]com
- icapturefilms[.]com
- iptvipstore[.]com
- ZLOADER C2s
- N/A
- SUPPORTING EVIDENCE
- https://twitter.com/ffforward/status/1318959441555881987
Add Comment
Please, Sign In to add comment