MalwareBreakdown

08/10/2020: ZLoader Campaign IOCs

Aug 10th, 2020 (edited)
17,091
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.91 KB | None | 0 0
  1. https://twitter.com/DynamicAnalysis/status/1292869239259488259
  2.  
  3. #ZLoader #malspam with .xls attachments.
  4.  
  5. Downloader URLs:
  6. https://chiarizzimooca-lancamento.com.br/wp-keys.php
  7. https://danyalpakhsh.ir/wp-keys.php
  8. https://flidot.com/wp-keys.php
  9. https://globalfilipino.net/wp-keys.php
  10.  
  11. .xls samples:
  12. https://app.any.run/tasks/28dc3476-2c2b-4f0c-b89e-0b0038ab06a4#
  13. https://app.any.run/tasks/ba1b2b5e-fcd8-475e-ae48-be7507eebff1
  14.  
  15. C2s:
  16. https://ahoeviwo.com/wp-parsing.php
  17. https://cga.cn/wp-parsing.php
  18. https://mementomori.vn/wp-parsing.php
  19. https://metodoking.com/wp-parsing.php
  20. https://flidot.com/wp-parsing.php
  21. https://nocusnanakindtu.tk/wp-parsing.php
  22. https://globalfilipino.net/wp-parsing.php
  23. https://chiarizzimooca-lancamento.com.br/wp-parsing.php
  24. https://geoflamonadrieve.tk/wp-parsing.php
  25. https://danyalpakhsh.ir/wp-parsing.php
  26.  
  27. .dll sample:
  28. https://app.any.run/tasks/96791cf1-fa33-4ba8-bd00-bda03e36d155
Add Comment
Please, Sign In to add comment