Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-07-28 - ZLOADER FROM RESUME-THEMED XLS SPREADSHEET
- REFERENCE:
- - https://twitter.com/malware_traffic/status/1288252759695925248
- MALWARE:
- - SHA256 hash: acdf04f8a8ea20b485aaa4f8f30b4be075775d5599b3006bbc020aba2a5d40b7
- - File size: 407,040 bytes
- - File name: resume.xls
- - File description: Password protected XLS file (password: 1234) with macro for ZLoader
- - SHA256 hash: 02846dbf25b333625a0720075fb47da62a946e5b0b4f9e9ba14cef514d576b37
- - File size: 520,192 bytes
- - File location: hxxp://205.185.125[.]104/files/july27.dll
- - File location: C:\mVVIuWs\FTBSEIh\cYNhXOc.dll
- - File location: C:\Users\[username]\AppData\Roaming\Itymuk\adavkie.dll
- - File run method: Rundll32.exe [filename],DllRegisterServer
- - File description: ZLoader malware DLL
- INFECTION TRAFFIC:
- - 205.185.125[.]104 port 80 - 205.185.125[.]104 - GET /MwRrN5
- - 205.185.125[.]104 port 80 - 205.185.125[.]104 - GET /files/july27.dll
- - 84.38.181[.]15 port 443 (HTTPS) - vlcafxbdjtlvlcduwhga[.]com - POST /web/post.php
- - 84.38.181[.]15 port 443 (HTTPS) - softwareserviceupdater3[.]com - POST /web/post.php
- - 84.38.181[.]15 port 443 (HTTPS) - softwareserviceupdater4[.]com - POST /web/post.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement