Advertisement
ExecuteMalware

2020-11-13 ZLoader IOCs

Nov 13th, 2020
9,007
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.94 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. # 595736 Many people from your firm will clearly be mad.
  5. Contract 63397946 reminder
  6. Contract No. 669 data
  7. Document 31516444 reminder
  8. Full summary of the Receipt ## 8332
  9. Nov. Unpaid Invoice
  10. Number 166336 Many people from your firm will definitely become mad.
  11. Number 195425 Some people inside your company will clearly get angry.
  12. Payment number 5650 information
  13. Re: Contract No. 669 data
  14. Statement 69156562 reminder
  15. Statement 71682924 sent by fax
  16. Statement 86089575 sent by fax
  17. Statement documents
  18. You have Overdue Invoice No.# 1509
  19.  
  20. SENDERS OBSERVED
  21. albertodar@eresmas.com
  22. albertoiradier@ciudad.com.ar
  23. AlexMurray@edinarealty.com
  24. allenchristopher207@aol.com
  25. francescoriol@eresmas.com
  26. kevin_j10@aol.com
  27. leelaura411@aol.com
  28. mervynthomas@btconnect.com
  29. pforbes@wilcoimaging.com
  30. robinsoncarol343@aol.com
  31. sharonkiff@btconnect.com
  32. tac13eka@aol.com
  33. tyco.67@aol.com
  34. wonil@sta.co.kr
  35. yolanda.paula@orange.es
  36.  
  37. EXCEL FILE HASHES
  38. 3628a52f8fe6c09823a7861af19b1cf7
  39. 6e3a84162fcae52d578ab632627109eb
  40. 91a833ce72cd873b2f52d2cf95294073
  41. cccd84bd8f272472cc76600c52de2587
  42. ee9612753190abfc6e04d980d8f61648
  43. f8dd148774e649e8c4d2c28814e08428
  44. fc4993c58495e9a2bbe584ecf041072d
  45.  
  46. EXCEL FILE NAMES
  47. 1509.xlsm
  48. 5650.xlsm
  49. 669.xls
  50. 8332.xls
  51. 8557.xls
  52. request.926.xls
  53. request6635.xls
  54.  
  55. ZLOADER PAYLOAD
  56. https://b-dvs.com/server.php
  57. https://b-design.studio/errors.php
  58. https://taigen-landscape.com/wp-crunch.php
  59. https://taigen-landspace.com/logs.php
  60.  
  61. https://topic.miami/wp-data.php
  62. https://topic.yoga/wp-data.php
  63.  
  64. b-dvs.com
  65. b-design.studio
  66. taigen-landscape.com
  67. taigen-landspace.com
  68. topic.yoga
  69. topic.miami
  70.  
  71. ZLOADER C2s
  72. https://azoltd.myzen.co.uk/errors.php
  73. https://enmasucitessee.tk/wp-smarts.php
  74. https://mandreskincare.com/wp-smarts.php
  75. https://moisbridge.co.uk/cp-panel.php
  76. https://pousadadosolbuzios.com.br/wp-smarts.php
  77. https://telkfitness.protekgr.com/errors.php
  78. https://tfbuildingjoinery.co.uk/errors.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement