ExecuteMalware

2020-08-10 ZLoader IOCs

Aug 10th, 2020
2,590
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.02 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Full summary of the Invoice # 5353
  3. Full summary of the Invoice No. 3710
  4. You have Incoming Invoice
  5.  
  6. SENDERS OBSERVED
  7. aelfthoefpuing11@aol[.]com
  8. gunwise_prancingtroll@aol[.]com
  9. robertsnancy53@aol[.]com
  10.  
  11. EXCEL FILE NAMES
  12. Hi3710[.]xls
  13. Jea_5353.xls
  14. Wu[.]1307[.]xls
  15.  
  16. EXCEL FILE HASHES
  17. 60cc345e6c801d5904a0d8efdcfa0e0d
  18. 3cc7496563da3abd4138fd0cda44a30b
  19.  
  20. ZLOADER PAYLOAD URLs
  21. hxxps://chiarizzimooca-lancamento[.]com[.]br/wp-keys[.]php
  22. hxxps://danyalpakhsh[.]ir/wp-keys[.]php
  23. hxxps://flidot[.]com/wp-keys[.]php
  24. hxxps://globalfilipino[.]net/wp-keys[.]php
  25.  
  26. ZLOADER C2s
  27. hxxps://ahoeviwo[.]com/wp-parsing[.]php
  28. hxxps://cga[.]cn/wp-parsing[.]php
  29. hxxps://chiarizzimooca-lancamento[.]com[.]br/wp-parsing[.]php
  30. hxxps://danyalpakhsh[.]ir/wp-parsing[.]php
  31. hxxps://flidot[.]com/wp-parsing[.]php
  32. hxxps://geoflamonadrieve[.]tk/wp-parsing[.]php
  33. hxxps://globalfilipino[.]net/wp-parsing[.]php
  34. hxxps://mementomori[.]vn/wp-parsing[.]php
  35. hxxps://metodoking[.]com/wp-parsing[.]php
  36. hxxps://nocusnanakindtu[.]tk/wp-parsing[.]php
Add Comment
Please, Sign In to add comment