bomccss

2020-10-28_Japanese-malspam_with-Zloader

Nov 5th, 2020
9,714
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.93 KB | None | 0 0
  1. <Subjects>
  2. 注文番号 AX000000-000000
  3. # X is random charactor, 0 is random number
  4.  
  5. <Attached File>
  6. 0000000.zip -> 0000000.xlsb
  7. # 0 is random number
  8.  
  9. <sample>
  10. https://app.any.run/tasks/8ab07f7b-0467-4e9f-b29e-db971531c65c/
  11. https://app.any.run/tasks/0c54ff74-a70d-4e02-89dc-39dc82bab8a9/
  12.  
  13. <Payload URL>
  14. # 3 patterns depending on the attached file
  15. hxxp://nightsalmon[.]xyz/campo/b/b
  16. (207.154.210[.]66)
  17. ->
  18. hxxp://tropicribs[.]com/wp-content/uploads/estate_templates/n1.exe
  19. (206.188.193[.]51)
  20.  
  21. hxxp://foreverbold[.]xyz/campo/b/b
  22. (207.154.210[.]66)
  23. ->
  24. hxxp://casevacanza[.]pro/wp-content/uploads/estate_templates/n1.exe
  25. (54.36.88[.]52)
  26.  
  27. hxxp://superstartart[.]xyz/campo/b/b
  28. (207.154.210[.]66)
  29. ->
  30. hxxp://www.brevmex[.]com/wp-content/uploads/estate_templates/n1.exe
  31. (160.153.72[.]68)
  32.  
  33. <Payload>
  34. https://app.any.run/tasks/d5151d34-4534-4441-ae20-74baa2b5afea/
  35.  
  36. <C2>
  37. hxxps://notsweets[.]net/LKhwojehDgwegSDG/gateJKjdsh.php
Add Comment
Please, Sign In to add comment