ExecuteMalware

2020-07-14 ZLoader IOCs

Jul 14th, 2020
2,783
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1.  
  2. THREAT ATTRIBUTION: ZLOADER
  3.  
  4. SUBJECTS OBSERVED
  5. Information regarding Invoice number 342
  6. Receipt information
  7.  
  8. SENDERS OBSERVED
  9. fellabeavergnome@aol[.]com
  10. soiganteliombor@aol[.]com
  11.  
  12. EXCEL FILE NAMES
  13. doc_342.xls
  14. inv-580[.]xls
  15.  
  16. EXCEL FILE HASHES
  17. 063e9e64c905eefa79800881edd0e839
  18. 11b765656fdd7ce6af47db2f79eaabb2
  19.  
  20. ZLOADER PAYLOAD URLs
  21. hxxps://australian-boots[.]nl/wp-keys[.]php
  22. hxxps://current9[.]com[.]ng/wp-keys[.]php
  23. hxxps://hotel-city[.]net/wp-keys[.]php
  24. hxxps://kinostanbulfilm[.]com/wp-keys[.]php
  25.  
  26. ZLOADER C2s
  27. hxxp://naochen[.]top/wp-parsing[.]php
  28. hxxp://raoxian[.]top/wp-parsing[.]php
  29. hxxp://shaoshun[.]top/wp-parsing[.]php
  30. hxxp://thaiblind[.]com/wp-parsing[.]php
  31. hxxp://wiremeshseller[.]com/wp-parsing[.]php
  32. hxxp://zameng[.]top/wp-parsing[.]php
  33. hxxp://zhuangque[.]top/wp-parsing[.]php
  34. hxxps://aserzietronun[.]tk/wp-parsing[.]php
  35. hxxps://tremmecontina[.]ga/wp-parsing[.]php
Add Comment
Please, Sign In to add comment