ExecuteMalware

2020-07-01 ZLoader IOCs

Jul 1st, 2020
4,318
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.31 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Agreement No 922 details
  5. Agreement Number 800 details from Vertex Brews
  6. Contract ID 346 info
  7. Invoice ## 728 info - from Cloud shack
  8. Receipt ID 836
  9. You have Overdue Invoice
  10. Your New service Invoice - number # 741
  11.  
  12. SENDERS OBSERVED
  13. geganlanorfind@aol[.]com
  14. gnancy73@aol[.]com
  15. janunelipoilba21i@aol[.]com
  16. nurikprusha@aol[.]com
  17. phillipscarol615@aol[.]com
  18. telwater.tobur1994i@aol[.]com
  19. woidegar_bowshield1984w9@aol[.]com
  20.  
  21. EXCEL FILE NAMES
  22. det[.]836[.]xls
  23. det800[.]xls
  24. order-346[.]xls
  25. Contract_100.xls
  26. order[.]922[.]xls
  27. Inf-728[.]xls
  28.  
  29. EXCEL FILE HASHES
  30. 6acbf602dcc8dca87be67394d7a29d7e
  31. 78ecc78f6854fa533b642ae7f37da854
  32. 860f11bf817164ceee98c51803874181
  33. 97f4364bf131e22e427ecc08fe2147a5
  34. d7dd42df72bf0dc89d1e3df46a44fd72
  35. e48784b86b027523837354ed29924223
  36.  
  37. ZLOADER PAYLOAD URLs
  38. hxxps://megamaq[.]com[.]ar/wp-keys[.]php
  39. hxxps://vietankhe[.]com[.]vn/wp-keys[.]php
  40. hxxps://bangrajan[.]org/wp-keys[.]php
  41. hxxps://noithatthongminhamd[.]com/wp-keys[.]php
  42.  
  43. ZLOADER C2s
  44. hxxps://alginis[.]com/wp-parsing[.]php
  45. hxxps://anuki[.]in/wp-parsing[.]php
  46. hxxps://cloudguchenleteli[.]gq/wp-parsing[.]php
  47. hxxps://pmi-print[.]de/wp-parsing[.]php
  48. hxxps://poikatamanfang[.]gq/wp-parsing[.]php
  49. hxxps://stockgainers[.]in/wp-parsing[.]php
  50. hxxps://tjiowa[.]com/wp-parsing[.]php
Advertisement
Add Comment
Please, Sign In to add comment