2020-04-03 - GERMAN AND ENGLISH MALSPAM PUSHING ZLOADER

ASSOCIATED FILES:

NOTES:

 

IMAGES


Shown above:  Example of German malspam pushing ZLoader from Thursday 2020-04-02.

 


Shown above:  Example of English malspam pushing ZLoader from Friday 2020-04-03.

 


Shown above:  Traffic from an infection filtered in Wireshark.

 


Shown above:  Folders created under the infected user's AppData\Roaming directory.

 


Shown above:  Windows registry update to keep this infection persistent.

 

Click here to return to the main page.