ExecuteMalware

2020-10-21 ZLoader IOCs

Oct 21st, 2020
2,944
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.11 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Additional information about Receipt # 2757
  5. Agreement ID 9804 info
  6. Information regarding invoice 9997
  7. This is your Customer Invoice -# 2587
  8.  
  9. SENDERS OBSERVED
  10. axelbs713@aol[.]com
  11. kevincarter689@aol[.]com
  12. kremilek28@aol[.]com
  13. nevestamg_80@aol[.]com
  14.  
  15. EXCEL FILE NAMES
  16. st[.]9804[.]xls
  17. Payment-2587[.]xls
  18. Det[.]2757[.]xls
  19.  
  20. EXCEL FILE HASHES
  21. 1e110417716b6e8d2688e2686e5d0687
  22. 20b29478852c93bbc2c3e19bec66af56
  23. e2314005d83eb68293b1cd932f0e6e11
  24.  
  25. ZLOADER PAYLOAD HASHES
  26. N/A
  27.  
  28. ZLOADER PAYLOAD URLs
  29. hxxps://albeeah[.]co/zg5ndr[.]php
  30. hxxps://digidraft[.]in/ve5hpk[.]php
  31. hxxps://htrackbrand[.]com/h0g6g6[.]php
  32. hxxps://htrackbrand[.]com/oltxgw[.]php
  33. hxxps://icapturefilms[.]com/jo4xyy[.]php
  34. hxxps://iptvipstore[.]com/a070ru[.]php
  35. hxxps://mail[.]htrackbrand[.]com/6bfcaf[.]php
  36. hxxps://recrugenie[.]cm/cqvlp9[.]php
  37.  
  38. albeeah[.]co
  39. htrackbrand[.]com
  40. mail[.]htrackbrand[.]com
  41. recrugenie[.]cm
  42. digidraft[.]in
  43. htrackbrand[.]com
  44. icapturefilms[.]com
  45. iptvipstore[.]com
  46.  
  47. ZLOADER C2s
  48. N/A
  49.  
  50. SUPPORTING EVIDENCE
  51. https://twitter.com/ffforward/status/1318959441555881987
Add Comment
Please, Sign In to add comment