Rewterz
Rewterz Threat Alert – Hive Ransomware Upgrades To Rust For More Improved Encryption Method – Active IOCs
July 6, 2022
Rewterz
Rewterz Threat Alert – RedLine Stealer – Active IOCs
July 6, 2022

Rewterz Threat Alert – ZLoader Banking Trojan – Active IOCs

Severity

High

Analysis Summary

ZLoader is also known as Terdot, DELoader, that loads the Zeus malware on victim machines after initial infection. It is a banking trojan. Like other banking trojans, It’s core capability is to harvest online account credentials for online banking sites (and some other services). When infected users land on a targeted online banking portal, malware dynamically fetches web injections from its command-and-control (C2) server to modify the page that the user sees, so that the information that the user enters into the log-in fields is sent to the cybercriminals. Attackers are found targeting victims with Invoice themed spear phishing malicious documents, in order to infect them with ZLoader. This wave of ZLoader samples also consists of files following the invoice-theme. The filenames are usually “invoice” or “case” with a special character like “.”, “-” or “_” followed by four random digits. The usual target is financial institutions and banks. ZLoader has multiple distribution methods. ZLoader was also found being distributed via malvertising campaigns earlier this September. Another campaign was found distributing ZLoader and other malware via Obfuscated VBScript in June

Impact

  • Credential Theft
  • Financial Theft
  • Data Exfiltration

Indicators of Compromise

MD5

  • 3f2036d6638df7dbeeaacd45d52c007b

SHA-256

  • 44ede6e1b9be1c013f13d82645f7a9cff7d92b267778f19b46aa5c1f7fa3c10b

SHA-1

  • fc747b3049c96afde43d91e6089da7d3865931b9

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.