2020-04-03 - GERMAN AND ENGLISH MALSPAM PUSHING ZLOADER
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2020-04-03-ZLoader-IOCs.txt.zip 2.4 kB (2,413 bytes)
- 2020-04-03-ZLoader-malspam-2-email-examples.zip 705 kB (704,703 bytes)
- 2020-04-03-ZLoader-infection-traffic.pcap.zip 217 kB (216,845 bytes)
- 2020-04-03-ZLoader-malware-and-artifacts.zip 1.6 MB (1,584,390 bytes)
NOTES:
- Follow-up info can be found in an ISC diary I wrote for Wednesday 2020-04-08 (link)
IMAGES
Shown above: Example of German malspam pushing ZLoader from Thursday 2020-04-02.
Shown above: Example of English malspam pushing ZLoader from Friday 2020-04-03.
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Folders created under the infected user's AppData\Roaming directory.
Shown above: Windows registry update to keep this infection persistent.
Click here to return to the main page.