ExecuteMalware

2020-07-20 ZLoader IOCs

Jul 20th, 2020
2,818
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.48 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Appointment inquire letter
  5. Followup letter to our dialogue
  6. Information about compensated purchase # 2235
  7. Reports you have wanted
  8.  
  9. SENDERS OBSERVED
  10. perallasilverwheels5@aol[.]com
  11. avebysignus@aol[.]com
  12. c.clark92@aol[.]com
  13. wulda_ironarrow1993y5@aol[.]com
  14.  
  15. EXCEL FILE NAMES
  16. V[.]246[.]xls
  17. 2235rzi[.]xls
  18. 9551du[.]xls
  19.  
  20. EXCEL FILE HASHES
  21. d361840ecbad5367afa7ee3432fb86fd
  22. a6633b2391698adbc145273e29a71f79
  23. a8468fb62bbcc0758eea1dcee1becc73
  24.  
  25. ZLOADER PAYLOAD URLs
  26. hxxps://ashok-poudel[.]com[.]np/wp-keys[.]php
  27. hxxps://atemschutzmasken-schutzmasken[.]de/wp-keys[.]php
  28. hxxps://aulaabierta[.]agoranews[.]es/wp-keys[.]php
  29. hxxps://ballista[.]vn/wp-keys[.]php
  30. hxxps://bdvan[.]com/wp-keys[.]php
  31. hxxps://bitcoincasinoreview[.]com/wp-keys[.]php
  32.  
  33. ZLOADER C2s
  34. hxxps://33x[.]us/wp-parsing[.]php
  35. hxxps://adealbox[.]com/wp-parsing[.]php
  36. hxxps://aeronchairbyhermanmiller[.]com/wp-parsing[.]php
  37. hxxps://bitvshe[.]club/wp-parsing[.]php
  38. hxxps://bkk-wertgeschaetzt[.]de/wp-parsing[.]php
  39. hxxps://bothigolfscuron[.]tk/wp-parsing[.]php
  40. hxxps://buydeel[.]com/wp-parsing[.]php
  41. hxxps://caixabanktalks-bancaprivada[.]agoranews[.]es/wp-parsing[.]php
  42. hxxps://cardskool[.]com/wp-parsing[.]php
  43. hxxps://cloudguchenleteli[.]gq/wp-parsing[.]php
  44. hxxps://tiawildlidapu[.]tk/wp-parsing[.]php
  45.  
  46. SUPPORTING EVIDENCE
  47. https://pastebin.com/raw/bb0RtM1u
  48. https://app.any.run/tasks/3ec42809-fca8-42f9-b9c9-6bf45425e564#
  49. https://app.any.run/tasks/735f5ec6-fb18-4c92-9d3f-bacf30a50083
Add Comment
Please, Sign In to add comment