Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2020-09-11 (FRIDAY) - MYRESUME.XLS PUSHES ZLOADER (SILENT NIGHT)
- TRAFFIC:
- - 205.185.113[.]20 port 80 - 205.185.113[.]20 - GET /PRTKfN
- - 205.185.113[.]20 port 80 - 205.185.113[.]20 - GET /files/911.dll
- - 31.184.253[.]244 port 80 - softwareserviceupdater5[.]com - POST /web/post.php
- MALWARE:
- - SHA256 hash: 421cccf7ef2ecd482467b2f470a28707447c39d581d11e39578f4dba4472fd71
- - File size: 159,232 bytes
- - File name: myResume.xls
- - File description: password-protected XLS file with macros for ZLoader (Silent Night)
- - SHA256 hash: 740577fb4e542f8f73b104ecf8e6890fc5ee3842f5393a9ce728117b11e7d7b3
- - File size: 631,808 bytes
- - File location: hxxp://205.185.113[.]20/files/911.dll
- - File location: C:\IDDCHrk\rWwiyCF\IYFLemb.dll
- - File location: C:\Users\[username]\AppData\Roaming\Noexun\ufvou.dll
- - File run method: regsvr32.exe /s [filename]
- - File description: DLL for ZLoader (Silent Night)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement