ExecuteMalware

2020-07-09 ZLoader IOCs

Jul 9th, 2020
3,074
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.05 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Information about invoice No610
  5. Invoicing No. 239 data
  6. Receipt number 485
  7. Your New service Invoice
  8.  
  9. SENDERS OBSERVED
  10. elgythtooshnak4j@aol[.]com
  11. gunar.selithrarion1990r@aol[.]com
  12. haraaksi_gasha@aol[.]com
  13. sapperwick_soifurj7@aol[.]com
  14.  
  15. EXCEL FILE NAMES
  16. pay-485[.]xls
  17. ref_75.xls
  18. Invoice-610[.]xls
  19. Pay239[.]xls
  20.  
  21. EXCEL FILE HASHES
  22. 1298427cff5bfad131f4b6d0ffb9ab3c
  23. 47fc241830728ef70305b0cdb72e89d8
  24. 9efffe461acae3ee36418ebd5adb9b6a
  25. a7638350bc3c243028cfb46ff09335c7
  26.  
  27. ZLOADER PAYLOAD URLs
  28. hxxp://merter[.]shop/wp-keys[.]php
  29. hxxp://pasca[.]fapet[.]ub[.]ac[.]id/wp-keys[.]php
  30. hxxp://pick20shop[.]shop/wp-keys[.]php
  31. hxxp://posviat[.]ru/wp-keys[.]php
  32.  
  33. ZLOADER C2s
  34. hxxp://draminski-retail[.]eu/wp-parsing[.]php
  35. hxxp://duanyong[.]top/wp-parsing[.]php
  36. hxxp://eternalstarculture[.]com/wp-parsing[.]php
  37. hxxp://gh99[.]cn/wp-parsing[.]php
  38. hxxp://glossy[.]vn/wp-parsing[.]php
  39. hxxps://nalighpicseracha[.]tk/wp-parsing[.]php
  40.  
  41. SUPPORTING EVIDENCE
  42. https://twitter.com/DynamicAnalysis/status/1281360949111382016
Add Comment
Please, Sign In to add comment