ExecuteMalware

2020-10-30 ZLoader IOCs

Oct 30th, 2020
3,731
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.45 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Additional information about Invoice id 2091
  5. Additional information about Invoice number 9814
  6. Agreement 1155 details
  7. Delayed account friendly reminder #: W710
  8. Delayed monthly bill friendly reminder #: E30
  9. Delayed monthly bill reminder ID: P01
  10. Details about Receipt No. 6295
  11. Outstanding monthly bill reminder ID: U142
  12. Outstanding payment message ID: P942
  13. Past due account reminder #: I80
  14. Past due payment notification CODE: P21
  15. Payment # 8187 info
  16.  
  17. SENDERS OBSERVED
  18.  
  19. EXCEL FILE HASHES
  20. 25ac4c15d4d14bea82577d5e7b55458e
  21. 356b5f6e2a2daa8b74a28f48288a61d0
  22. 43cb32046de416192df108145c9625cb
  23. 86b16147f0c864a4d88cc0d6f7bb742e
  24. b31eb610d51dce4bb45ee49a3e2e31a8
  25. b5b631a0148c11a571a8e0098a23e541
  26. c8a5b3c6e5e120b5afb202564e9fe68a
  27. f5004a15365709fb2e2a1dcd3c8d69e6
  28.  
  29. ZLOADER PAYLOAD
  30. https://access-one.us/aym3vh.php
  31. https://amazonuniverse.in/a1cunn.php
  32. https://creditoacumuladoicms.com.br/njcnt1.php
  33. https://longisland.casa/wp-data.php
  34. https://morgadoent.co.za/tizmel.php
  35. https://payment.fashion/wp-data.php
  36.  
  37. access-one.us
  38. amazonuniverse.in
  39. creditoacumuladoicms.com.br
  40. longisland.casa
  41. morgadoent.co.za
  42. payment.fashion
  43.  
Add Comment
Please, Sign In to add comment