ExecuteMalware

2020-06-03 ZLoader IOCs

Jun 3rd, 2020
3,977
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.19 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. 4064863 agreement invoicing assumed
  3. Additional invoicing #9576172
  4. Agreement approval
  5. Awaiting an early reply
  6. Case 1495566: invoice 1495566 is blocked
  7. Info 7576571 you had asked for
  8. Information 8329355
  9. Invoice 1718226 is accepted
  10. Invoice 9857068 is accepted
  11. Invoice transaction ID 4623390 completed
  12. Invoice transfer ID 9456005 confirmed
  13. Payment 7897868 for given invoice 7897868 is approved
  14. Yearly invoicing #2167619
  15. Yearly invoicing #6876357
  16.  
  17. SENDERS OBSERVED
  18.  
  19. EXCEL FILE HASHES
  20. Notif-4192317.xls
  21. 120200a1e082af4b240e946d67737217
  22.  
  23. ZLOADER PAYLOAD FILE HASHES
  24. yn.dll
  25. a3d9b510e2e17f4ea08aa9f74b54e6b5
  26.  
  27. ZLOADER PAYLOAD URLs
  28. https://psychotherapyresources.org/wp-data.php
  29. https://palchik.club/wp-data.php
  30.  
  31. ZLOADER C2s
  32. https://ticlatchmisrato.tk/wp-parser.php
  33.  
  34. Also:
  35. https://app.any.run/tasks/d19b3875-e476-4191-81cf-eb810d12d014/
Add Comment
Please, Sign In to add comment