Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: ZLOADER
- SUBJECTS OBSERVED
- Information regarding Invoice number 342
- Receipt information
- SENDERS OBSERVED
- fellabeavergnome@aol[.]com
- soiganteliombor@aol[.]com
- EXCEL FILE NAMES
- doc_342.xls
- inv-580[.]xls
- EXCEL FILE HASHES
- 063e9e64c905eefa79800881edd0e839
- 11b765656fdd7ce6af47db2f79eaabb2
- ZLOADER PAYLOAD URLs
- hxxps://australian-boots[.]nl/wp-keys[.]php
- hxxps://current9[.]com[.]ng/wp-keys[.]php
- hxxps://hotel-city[.]net/wp-keys[.]php
- hxxps://kinostanbulfilm[.]com/wp-keys[.]php
- ZLOADER C2s
- hxxp://naochen[.]top/wp-parsing[.]php
- hxxp://raoxian[.]top/wp-parsing[.]php
- hxxp://shaoshun[.]top/wp-parsing[.]php
- hxxp://thaiblind[.]com/wp-parsing[.]php
- hxxp://wiremeshseller[.]com/wp-parsing[.]php
- hxxp://zameng[.]top/wp-parsing[.]php
- hxxp://zhuangque[.]top/wp-parsing[.]php
- hxxps://aserzietronun[.]tk/wp-parsing[.]php
- hxxps://tremmecontina[.]ga/wp-parsing[.]php
Add Comment
Please, Sign In to add comment