ExecuteMalware

2020-06-05 ZLoader IOCs

Jun 5th, 2020
3,216
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.68 KB | None | 0 0
  1. SUBJECTS OBSERVED
  2. Fw:Actual equipment charge
  3. FW:Affirmed gear statement
  4. Fw:Awaiting an quick reply
  5. FW:Composed document
  6. Fw:Doc 1294535: facsimile duplicate
  7. FW:Fax sent, an answer required
  8. Fw:Info 8458834 that you had requested
  9. RE:Docs 5130897 you had asked for
  10. Re:Forwarded fax letter
  11. Re:Looking forward for an quick answer
  12. Re:Payment details 9960436
  13. Re:Statement 1303095 sent by fax
  14.  
  15. SENDERS OBSERVED
  16. secoconcasul1976@interia.pl
  17. caiplanacenub1973@interia.pl
  18. graner3578@interia.pl
  19. propoc3019@interia.pl
  20. anbaicelbuymi1975@interia.pl
  21. doorfning3264@interia.pl
  22. menthe.windweens@interia.pl
  23. exom3222@interia.pl
  24. caykoi.siehten@interia.pl
  25. rona.chanka@interia.pl
  26. chortai.bolgwi@interia.pl
  27. factrag.cioke@interia.pl
  28.  
  29. EXCEL FILE HASHES
  30. 175086498bf0de834d2981419b1f49cf
  31. 1b1023a3fe4e928ff7e353ed5be300c0
  32. 4692dd299e5e7c3e5e918dccb53dc3ef
  33. 4dccd6058dde5eff85b6a11117b7b388
  34. 8344d3a72817863b14e6d8fc0fd18faf
  35. 904c5d015e2bf428adbc9d394a1fab66
  36. ab6afb3d45c83b8370914f737c708d12
  37. b3a3bbbe4d9ec50c2685007b563370ce
  38. cb35560efc26cb77752846d58fe8604d
  39.  
  40. ZLOADER PAYLOAD FILE HASHES
  41. FSRlqg.html
  42. 82383c51deb1f62e6573e567d03a254c
  43.  
  44. w.dll
  45. 892fbc87fdbcbe9d91e17ae7355eb54c
  46.  
  47. ZLOADER PAYLOAD URLS
  48. http://lauwang.vn/wp-keys.php
  49. http://visionmedia.vn/wp-keys.php
  50. https://naorietenderpver.gq/wp-keys.php
  51. https://placanemcourri.ga/wp-keys.php
  52. https://regerfederer.club/wp-data.php
  53. https://sharkweek2019.best/wp-data.php
  54.  
  55. https://chromenerlitigub.tk/ews/w.dll
  56. https://riesperetidtur.tk/fwef.php
  57.  
  58. ZLOADER C2s
  59. http://cld.kazgau.com/wp-parser.php
  60. http://janekleeb.com/wp-parser.php
  61. https://cmso.med.cmu.ac.th/wp-parser.php
  62. https://gahotimaskever.ga/wp-parser.php
  63. https://tlenexicagopca.tk/wp-parser.php
Add Comment
Please, Sign In to add comment