ExecuteMalware

2020-05-07 ZLoader IOCs

May 7th, 2020
2,081
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.74 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Customer Invoice - ID4897
  3. May Service Invoice
  4. You have Service Invoice
  5. Your Incoming Invoice - Number#879
  6. Your Incoming Invoice id#1242
  7. Your Service Invoice No #5380, Electra Enterprises
  8.  
  9. SENDERS OBSERVED
  10. athelred.vridash2c@aol.com
  11. berhwald_vimakk@aol.com
  12. fladnor.golin19998v@aol.com
  13. jeipekkamimi8@aol.com
  14. thugnuseowadriendir15e@aol.com
  15. withinggladebamli18h5@aol.com
  16.  
  17. EXCEL FILE HASHES
  18. Qd_9823.xls
  19. 61b6bb095b1ccf1cb6f590bd5cef77e4
  20.  
  21. ZLOADER PAYLOAD URLs
  22. http://wp.regalporn.com/wp-keys.php
  23. http://qmwechat.cn/wp-keys.php
  24.  
  25. http://www.mothersdryfruits.com/wp-content/uploads/2020/04/fg3rg.php
  26.  
  27. ZLOADER C2s
  28. https://rswtgmhf.pw/wp-config.php
  29. https://fwgdhdln.icu/wp-config.php
  30. https://nukoqcftavbbyeqrshkx.com/post.php
Add Comment
Please, Sign In to add comment