ExecuteMalware

2020-09-30 Zloader IOCs

Sep 30th, 2020
3,575
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.63 KB | None | 0 0
  1. THREAT ATTRIBUTION: ZLOADER
  2.  
  3. SUBJECTS OBSERVED
  4. Details about Invoice Number 1856
  5. Information regarding Invoice ID 2470
  6. Invoice 9903 information
  7.  
  8. SENDERS OBSERVED
  9.  
  10. EXCEL FILE NAMES
  11. in-9903.xls
  12. ord2470.xls
  13. PQ-1856.xls
  14.  
  15. EXCEL FILE HASHES
  16. 5026b968321946721f085536cdf43236
  17. 52d6f1f0ed2fe989985990cbae6a1d45
  18. afe44d0d18616d1b2080c9d1078f4c8e
  19.  
  20. ZLOADER PAYLOAD HASHES
  21. None
  22.  
  23. ZLOADER PAYLOAD URLs
  24. https://eshelmet.com/wp-touch.php
  25. https://ezs.com.au/wp-touch.php
  26. https://jonescustombuilds.com/wp-touch.php
  27. https://laspanofashion.com/wp-touch.php
  28.  
  29. ZLOADER C2s
  30. UNKNOWN
Add Comment
Please, Sign In to add comment