ExecuteMalware

2020-04-21 ZLoader IOCs

Apr 21st, 2020
2,533
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.78 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Apr. New incoming Invoice number#23981
  3. Bank check for statement 828573
  4. Case 808565: invoice 808565 is freezed
  5. Check for invoice 476349
  6. Check for statement 229981
  7. Given invoice 196670 successfully filed
  8. Given invoice 606970 fully filed
  9. Invoice 600049 is processed
  10. New service Invoice - ID4998, Bullimited
  11. Pay-slip for statement 717337
  12. Payment for invoice 221480 is not accepted
  13. Payment for invoice 496908 is not accepted
  14. Payment for receipt 928875 is important
  15. Settlement for invoice 660168 is required
  16. Settlement for receipt 937446 is required
  17.  
  18. SENDERS OBSERVED
  19. chone.nobuck1976@o2.pl
  20. cilna.galmi1971@o2.pl
  21. etplan.weepbe1979@o2.pl
  22. kalto.bare1975@o2.pl
  23. laving.fromwea1980@o2.pl
  24. leroilbabeaverdeerv3@aol.com
  25. maco.fecfi1977@o2.pl
  26. morttram.imer1985@o2.pl
  27. nikuron.beriadecan19972@aol.com
  28. nsumem.anes1971@o2.pl
  29. perfuns.profin1978@o2.pl
  30. righgand.inoc1982@o2.pl
  31. sembjunk.paldo1981@o2.pl
  32. tcholun.nisca1984@o2.pl
  33. titef.cydys1980@o2.pl
  34.  
  35. EXCEL FILE HASHES
  36. 05eb5023ffaa9df0b769d350a68bd22d
  37. 067d5c1167a2c16110e05c76c761fdf3
  38. 0cab7e21872f4c55904cefc351a33909
  39. 120175e0b4e6d2d3e32618c61b999530
  40. 26c5f5e98a105b968f8941211a3000d6
  41. 33ed2505f6333421c686a2871b2255f0
  42. 4abb68a9d115ceebefb5f2a2c9d6fee3
  43. 6a1ceeff455c6f80657bc792d0e6d9f3
  44. 8cf84ff1311338b246043e2c6eaaea31
  45. 9d75c22e898e504d624d3f1ae0016547
  46. a5f50ad3ff7512b0494bb85519ce60a1
  47. c6a1fd2faf88cec674346567b1173f86
  48. ff9416c3e46581e70b8e613b71a2cb7d
  49.  
  50. ZLOADER PAYLOAD URLs
  51. http://teachertoh.com/wp-content/themes/calliope/wp-front.php
  52. http://topspeedfitness.com.my/blog/wp-content/themes/calliope/wp-front.php
  53. http://maesimplesmente.com/wp-admin/includes/wp-smart.php
  54.  
  55. http://195.2.93.15/z.dll
  56.  
  57. ZLOADER C2s
  58. https://glsunzdf.casa/wp-config.php
  59. https://xaprgnve.icu/wp-config.php
  60. https://ualdfdjoevspjtpilbtb.com/post.php
Add Comment
Please, Sign In to add comment