MalwareBreakdown

08/05/2020: ZLoader Campaign IOCs

Aug 5th, 2020 (edited)
17,177
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.04 KB | None | 0 0
  1. https://twitter.com/DynamicAnalysis/status/1291050783480348673
  2.  
  3. #ZLoader #malspam with .xls attachments.
  4.  
  5. Recent downloader URLs
  6.  
  7. https://luckyprizewon.xyz/wp-index.php
  8. https://modifikasi.xyz/wp-index.php
  9. https://fuefutingtourmomi.tk/wp-index.php
  10. https://sympmatidoorslo.tk/wp-index.php
  11.  
  12. .xls sample:
  13. https://app.any.run/tasks/8bfb794e-0393-4194-a8db-545f75676fda
  14.  
  15. https://channelmelabd.com/wp-keys.php
  16. https://ezy.id/wp-keys.php
  17. https://ksuengineering.com/wp-keys.php
  18. https://laserdoctor.com.br/wp-keys.php
  19.  
  20. .xls sample:
  21. https://app.any.run/tasks/22c59613-7b2f-48c7-a1bd-473b49a96bad
  22.  
  23.  
  24.  
  25. C2s:
  26.  
  27. https://hhbiao.com/wp-parsing.php
  28. https://web.job2go.net/wp-parsing.php
  29. https://i9a.cn/wp-parsing.php
  30. https://billibazar.com/wp-parsing.php
  31. https://th.plus/wp-parsing.php
  32. https://nieguanabchisibi.cf/wp-parsing.php
  33. https://desigrocer.com/wp-parsing.php
  34. https://96bkj.cn/wp-parsing.php
  35. https://nedinilorreca.tk/wp-parsing.php
  36.  
  37. .dll sample:
  38. https://bazaar.abuse.ch/sample/6943af74133b5003dd39c65473d54749c131536d8fd773801de2e80ede8e0c0a/
Add Comment
Please, Sign In to add comment