ExecuteMalware

2020-09-03 ZLoader IOCs

Sep 3rd, 2020
3,766
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.74 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Receipt No. 10000
  5. Sept. New service Invoice, ID # 9416
  6.  
  7. SENDERS OBSERVED
  8.  
  9. EXCEL FILE NAMES
  10. in10000.xls
  11. Qt.9416.xls
  12.  
  13. EXCEL FILE HASHES
  14. 04EE27991B19322F96131B7E81667369B1156D63CEF4F81AA86E7AE43FFC8C11
  15. 102322065FF0BCF670B819017BC12788DB940403BF9FABAABEF0A1C63ECCF832
  16.  
  17. ZLOADER PAYLOAD URLs
  18. https://divocdiagnostics.com/wp-keys.php
  19. https://educationcrypto.io/wp-keys.php
  20. https://gamehub.ee/wp-keys.php
  21. https://hatcuomhoainhu.com/wp-keys.php
  22.  
  23. divocdiagnostics.com
  24. educationcrypto.io
  25. gamehub.ee
  26. hatcuomhoainhu.com
  27.  
  28. ZLOADER C2s
  29. https://www.4fishing.it/wp-parsing.php
  30. https://adsnoinsta.com/wp-parsing.php
  31.  
  32. 4fishing.it
  33. adsnoinsta.com
Add Comment
Please, Sign In to add comment