Advertisement
MalwareBreakdown

06/19/2020: ZLoader Campaign IOCs

Jun 20th, 2020
13,175
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.35 KB | None | 0 0
  1. Follow me at https://twitter.com/DynamicAnalysis
  2.  
  3. Reference at https://twitter.com/DynamicAnalysis/status/1274271073597456385
  4.  
  5. #ZLoader #malspam with .xls attachments.
  6.  
  7. Downloader URLs include:
  8. https://reinin.tw/wp-keys.php
  9. https://legendcoder.com/wp-keys.php
  10. https://pullingmezcnarcmer.tk/wp-keys.php
  11. https://ruibrunconcallconsta.tk/wp-keys.php
  12.  
  13. Malware payload:
  14. https://tiilearaphefanpa.gq/g34gc.php
  15.  
  16. #ZLoader C2s:
  17. https://thebypath.com/wp-parsing.php
  18. https://dramalove.su/wp-parsing.php
  19. https://hongsamlinhchi.vn/wp-parsing.php
  20. https://monquasuckhoe.com/wp-parsing.php
  21. https://nhansamlinhchi.com.vn/wp-parsing.php
  22.  
  23. XLS Sample:
  24. https://app.any.run/tasks/c231a3ac-37c6-4e69-8f48-17ddcf926fc6/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement