Advertisement
MalwareBreakdown

07/01/2020: ZLoader Campaign IOCs

Jul 1st, 2020
12,344
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.73 KB | None | 0 0
  1. https://twitter.com/DynamicAnalysis/status/1278359026690961408
  2.  
  3. #ZLoader #malspam with .xls attachment from today has a slight change... No redirect was found to a secondary domain where the .dll was downloaded.
  4.  
  5. Below are the downloader URLs:
  6.  
  7. s://megamaq.com.ar/wp-keys.php
  8. s://vietankhe.com.vn/wp-keys.php
  9. s://bangrajan.org/wp-keys.php
  10. s://noithatthongminhamd.com/wp-keys.php
  11.  
  12. #ZLoader C2s:
  13.  
  14. https://alginis.com/wp-parsing.php
  15. https://stockgainers.in/wp-parsing.php
  16. https://poikatamanfang.gq/wp-parsing.php
  17. https://tjiowa.com/wp-parsing.php
  18. https://pmi-print.de/wp-parsing.php
  19. https://anuki.in/wp-parsing.php
  20. https://cloudguchenleteli.gq/wp-parsing.php
  21.  
  22. XLS sample:
  23. https://app.any.run/tasks/ba0b4739-44ec-4d0f-ab91-092acd037384#
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement