ExecuteMalware

2020-08-05 ZLoader IOCs

Aug 5th, 2020
2,487
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.24 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Chat follow-up email with Agreement for Services
  5. Detailed Invoice Number 1482
  6.  
  7. SENDERS OBSERVED
  8. eorpwulf_traol@aol[.]com
  9. oteof[.]rigor@aol[.]com
  10.  
  11. EXCEL FILE NAMES
  12. ta1482[.]xls
  13. py9350[.]xls
  14.  
  15. EXCEL FILE HASHES
  16. bf149abab587514619125c2ec3f54ac4
  17. ef74d2b888b8acc039e25f6494d98064
  18.  
  19. ZLOADER PAYLOAD URLs
  20. hxxps://channelmelabd[.]com/wp-keys[.]php
  21. hxxps://ezy[.]id/wp-keys[.]php
  22. hxxps://fuefutingtourmomi[.]tk/wp-index[.]php
  23. hxxps://ksuengineering[.]com/wp-keys[.]php
  24. hxxps://laserdoctor[.]com[.]br/wp-keys[.]php
  25. hxxps://luckyprizewon[.]xyz/wp-index[.]php
  26. hxxps://modifikasi[.]xyz/wp-index[.]php
  27. hxxps://sympmatidoorslo[.]tk/wp-index[.]php
  28.  
  29. ZLOADER C2s
  30. hxxps://96bkj[.]cn/wp-parsing[.]php
  31. hxxps://billibazar[.]com/wp-parsing[.]php
  32. hxxps://desigrocer[.]com/wp-parsing[.]php
  33. hxxps://hhbiao[.]com/wp-parsing[.]php
  34. hxxps://i9a[.]cn/wp-parsing[.]php
  35. hxxps://nedinilorreca[.]tk/wp-parsing[.]php
  36. hxxps://nieguanabchisibi[.]cf/wp-parsing[.]php
  37. hxxps://th[.]plus/wp-parsing[.]php
  38. hxxps://web[.]job2go[.]net/wp-parsing[.]php
  39.  
  40. SUPPORTING EVIDENCE
  41. I opened the malicious documents in my lab and captured the IOCs dynamically.
  42.  
  43. Also:
  44. hxxps://twitter[.]com/DynamicAnalysis/status/1291059343517986816
Add Comment
Please, Sign In to add comment