ExecuteMalware

2020-05-12 ZLoader IOCs

May 12th, 2020
2,461
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.51 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. 7730104 contract invoicing assumed
  3. Agreement 7845441 sent by fax
  4. Awaiting an early answer
  5. Awaiting an early feedback
  6. Awaiting an early respond
  7. Case 4207191: invoice 4207191 is freezed
  8. Case 8667404: invoice 8667404 is suspended
  9. Case 9408770: invoice 9408770 is freezed
  10. Compensated receipt 7111046
  11. Doc 5359605: faxed duplicate
  12. Doc 6978949: facsimile duplicate
  13. Doc 8402104: facsimile dupl.
  14. Fax documentation 4073917
  15. Fax documents 3044564
  16. Fax prepared, an answer required
  17. Fax received, a feedback required
  18. Fax sent, a feedback needed
  19. Faxing documentation 3273159
  20. Invoice 3375695 is processed
  21. Invoice 4810779
  22. Invoice 6776031
  23. Invoice 6988049
  24. Invoice transfer ID 4652923 completed
  25. Looking forward for an quick respond
  26. Looking forward to an early answer
  27. Looking forward to an early feedback
  28. Pay-slip for receipt 7247682
  29. Paycheck for statement 7869411
  30. Payment 1124304 for given invoice 1124304 is approved
  31. Payment 2290762 for given invoice 2290762 is approved
  32. Payment 3673462 for given invoice 3673462 is approved
  33. Payment 3859814 for given invoice 3859814 is received
  34. Payment 6640463 for sent invoice 6640463 is received
  35. Payment 9931103 for given invoice 9931103 is approved
  36. Payment check under contract # 5469785
  37. Receipt 7433885 was faxed
  38. Receipt 8310051 successfully filed
  39. Receipt 9885271 fully compensated
  40. Receipt under agreement # 9172889
  41. Sent fax message
  42. Watching for an fast reply
  43.  
  44. SENDERS OBSERVED
  45. ableg.hazra1979@o2.pl
  46. agthrit.starov1987@o2.pl
  47. alka.leokai1987@o2.pl
  48. apos.keappcap1989@o2.pl
  49. beyni.beachpa1981@o2.pl
  50. bobsflat.coffcant1989@o2.pl
  51. charsimp.adok1977@o2.pl
  52. dores.saydi1977@o2.pl
  53. insic.duitor1970@o2.pl
  54. letown.maco1978@o2.pl
  55. loator.lesu1989@o2.pl
  56. lofa.anex1976@o2.pl
  57. marplea.anber1974@o2.pl
  58. merdei.orol1983@o2.pl
  59. mmennat.cracin1971@o2.pl
  60. neyru.sighde1981@o2.pl
  61. niaflak.rivors1975@o2.pl
  62. pacomp.sidhcu1985@o2.pl
  63. pargu.dietouch1975@o2.pl
  64. pema.esna1974@o2.pl
  65. pome.accur1988@o2.pl
  66. prochug.knurcumb1973@o2.pl
  67. puncking.ilry1976@o2.pl
  68. rentni.sturez1971@o2.pl
  69. retcount.voiro1970@o2.pl
  70. sioland.inan1974@o2.pl
  71. slater.checkrou1974@o2.pl
  72. smaler.ocnet1980@o2.pl
  73. smariz.lica1977@o2.pl
  74. sobe.tiopa1989@o2.pl
  75. softprop.cesslu1983@o2.pl
  76. sonla.utys1977@o2.pl
  77. sori.dowvans1979@o2.pl
  78. soundmisp.unen1984@o2.pl
  79. tano.giede1985@o2.pl
  80. tennons.taiscuf1971@o2.pl
  81. thiemul.ades1971@o2.pl
  82. tioslid.speedge1986@o2.pl
  83. tise.inac1979@o2.pl
  84. warpa.terpcrep1981@o2.pl
  85. warve.miha1975@o2.pl
  86.  
  87. EXCEL FILE HASHES
  88. 0d99e1cb78348fc11fb11d85f159a252
  89. 1ef8c86bd6c60a9ce255d1f5823c4756
  90. 238f1aac2023818e40456608fb1071ee
  91. 38b6151c80a4cb2ded51ea0dc297c793
  92. 5c87d328334e2aa0e432394ec184cc7b
  93. 5d9af4b1c8d8db7994cb0f8d00260350
  94. 870cb5dbe69e3ecd4bebb381d677ab5d
  95. 8ddd3d4e666fb820f43dd6211b5b80bd
  96. a196d6b3169c242496e77528194fd742
  97. a8b03c2b4dfba73cf6a013484515fc93
  98. a8e9647c0485993d94fbc9906b1e0df1
  99. b45cb6adc305678baa1a061417da3dcc
  100. c75ccce1badd10d210b5677805d5be8a
  101. e293bcd44c8c410ca45484a4d096831b
  102. f32d7b247434533375577ecdbcd636f6
  103.  
  104. ZLOADER PAYLOAD FILE HASHES
  105. 2.dll
  106. 3188d2f01ddf123f02b626c390886f66
  107.  
  108. x.dll
  109. c1366b1afc57e2fca68501345bbd4ba0
  110.  
  111. ZLOADER PAYLOAD URLs
  112. https://gavrelets.ru/wp-keys.php
  113. https://japanjisho.info/wp-keys.php
  114. https://mycoursera.in/wp-content/uploads/2020/05/wp-front.php
  115. https://stoplazyconf.com/wp-front.php
  116.  
  117. https://hopime.com/wp-content/plugins/apikey/2.dll
  118. http://95.181.152.73/l/x.dll
  119.  
  120. ZLOADER C2s
  121. https://japanjisho.info/wp-parser.php
  122. https://home.comegico.com.mx/wp-parser.php
  123. https://hormonas.comegico.com.mx/wp-parser.php
  124. https://hopime.com/wp-parser.php
  125. https://gavrelets.ru/wp-parser.php
Add Comment
Please, Sign In to add comment