<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress.com" -->
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:image="http://www.google.com/schemas/sitemap-image/1.1" xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd"><url><loc>https://zerophagemalware.com/2019/07/24/july-24-2019-an-update-on-what-ive-been-up-to/</loc><lastmod>2019-07-24T11:37:24+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/about/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/zerophageicon21.png</image:loc><image:title>zerophageicon2</image:title></image:image><lastmod>2019-07-24T10:50:08+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://zerophagemalware.com/2018/08/17/rig-ek-via-hookads-drops-azorult-loading-quasar-rat/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/qusarratdrop.png</image:loc><image:title>qusarRATdrop</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/threats.png</image:loc><image:title>Threats</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/appout.png</image:loc><image:title>appout</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/azorultquasarappany.png</image:loc><image:title>AzoRultQuasarAppAny</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/quasarratout2.png</image:loc><image:title>QuasarRATOut2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/quasarratout.png</image:loc><image:title>QuasarRATOUT</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/azorult2.png</image:loc><image:title>Azorult2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/azorult1.png</image:loc><image:title>AzoRult1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/rigcatch.png</image:loc><image:title>RigCatch</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/08/hookadsdecode.png</image:loc><image:title>HookAdsDecode</image:title></image:image><lastmod>2018-08-17T16:23:00+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/06/15/gransoftek-drops-gandcrab-via-ascentor-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/downloadgand.png</image:loc><image:title>downloadgand</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/urlscan2.png</image:loc><image:title>urlscan2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/urlscan1.png</image:loc><image:title>urlscan1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/strings2.png</image:loc><image:title>strings2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/stringsloader.png</image:loc><image:title>stringsLoader</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/htadownload.png</image:loc><image:title>HTADownload</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/scripthta.png</image:loc><image:title>scripthta</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/cve.png</image:loc><image:title>CVE</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/grandtttraffic.png</image:loc><image:title>GrandTttraffic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/06/scriptonpage.png</image:loc><image:title>scriptonpage</image:title></image:image><lastmod>2018-06-20T08:01:07+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/05/22/rig-ek-via-ngay-drops-smokeloader-xmr-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/miner.png</image:loc><image:title>miner</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/any5.png</image:loc><image:title>any5</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/any3.png</image:loc><image:title>any3</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/any4.png</image:loc><image:title>any4</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/any2.png</image:loc><image:title>any2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/any1.png</image:loc><image:title>any1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/compsite.png</image:loc><image:title>compsite</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/05/ngay.png</image:loc><image:title>Ngay</image:title></image:image><lastmod>2018-05-22T23:47:33+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/04/16/rig-ek-via-malvertising-drops-smoke-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/vitali.png</image:loc><image:title>Vitali</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/chaps3.png</image:loc><image:title>chaps3</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/chaps4.png</image:loc><image:title>chaps4</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/chaps2.png</image:loc><image:title>chaps2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/chaps1.png</image:loc><image:title>chaps1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/bhat.png</image:loc><image:title>Bhat</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/initialtweet.png</image:loc><image:title>InitialTweet</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/anyrun.png</image:loc><image:title>AnyRun</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/rigsmokepic.png</image:loc><image:title>RigSmokePic</image:title></image:image><lastmod>2018-04-16T16:08:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/04/09/rig-ek-drops-gandcrab-ransomware-via-fcve-2018-4878/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/flashpart.png</image:loc><image:title>Flashpart</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/gandcrab.png</image:loc><image:title>GandCrab</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/gandcrab2.png</image:loc><image:title>GandCrab2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/flashexploit.png</image:loc><image:title>FlashExploit</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/rigeklandingpage.png</image:loc><image:title>RigEkLandingPAge</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/04/rigekgandcrab.png</image:loc><image:title>RigEKGandCrab</image:title></image:image><lastmod>2018-04-09T23:49:12+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/02/10/grandsoft-ek-via-slots-drops-leviarcoin-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/domain.png</image:loc><image:title>domain</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/hash2.png</image:loc><image:title>hash2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/hashes.png</image:loc><image:title>hashes</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/payloaddrop.png</image:loc><image:title>payloaddrop</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/minercoin.png</image:loc><image:title>minercoin</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/processspam.png</image:loc><image:title>processspam</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/grandsoft2.png</image:loc><image:title>GrandSoft2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/grandsoft1.png</image:loc><image:title>GrandSoft1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/slotsredirect.png</image:loc><image:title>Slotsredirect</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/02/grandsoftminer.png</image:loc><image:title>GrandSoftMiner</image:title></image:image><lastmod>2018-02-10T00:20:49+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2018/01/23/maldoc-rtf-drop-loda-logger/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/01/lodac2.png</image:loc><image:title>lodac2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/01/scriptlet.png</image:loc><image:title>scriptlet</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/01/phishing-email.png</image:loc><image:title>phishing email</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/01/lodalogger.png</image:loc><image:title>LodaLogger</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2018/01/lodapic.png</image:loc><image:title>lodapic</image:title></image:image><lastmod>2018-01-23T13:17:01+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/12/11/malware-snatch-loader-reloaded/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/capture.png</image:loc><image:title>Capture</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/uploads.png</image:loc><image:title>uploads</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/admin.png</image:loc><image:title>admin</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/c2.png</image:loc><image:title>C2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/exc2.png</image:loc><image:title>exc2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/trusted.png</image:loc><image:title>trusted</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/processes.png</image:loc><image:title>Processes</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/12/c2first.png</image:loc><image:title>C2First</image:title></image:image><lastmod>2017-12-11T01:38:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/10/17/rig-ek-drops-ursnifisfb-variant/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/post.png</image:loc><image:title>POST</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/datastore.png</image:loc><image:title>datastore</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/webinjects.png</image:loc><image:title>webinjects</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/folder.png</image:loc><image:title>Folder</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/copy.png</image:loc><image:title>copy</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/zinkhole.png</image:loc><image:title>zinkhole</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/3021.png</image:loc><image:title>302</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/uirsnifrifg.png</image:loc><image:title>UIrsnifRifg</image:title></image:image><lastmod>2017-10-17T18:58:15+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/10/14/rig-ek-drops-smoke-loaders-leading-to-xmr-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/miner.png</image:loc><image:title>miner</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/minercopmms.png</image:loc><image:title>minercopmms</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/rigminer2.png</image:loc><image:title>rigminer</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/smokeloader1.png</image:loc><image:title>SmokeLoader1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/compromised-site.png</image:loc><image:title>compromised site</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/xmrrig.png</image:loc><image:title>XMRRig</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/infos.png</image:loc><image:title>infos</image:title></image:image><lastmod>2017-10-14T19:08:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/10/13/rig-ek-via-malvertising-drops-a-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/rigminer1.png</image:loc><image:title>RigMiner</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/smoke.png</image:loc><image:title>smoke</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/smoke2.png</image:loc><image:title>smoke2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/uwotm8.png</image:loc><image:title>UWOTM8</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/final.png</image:loc><image:title>final</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/gege.png</image:loc><image:title>gege</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/302.png</image:loc><image:title>302</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/30222.png</image:loc><image:title>30222</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/rigminer.png</image:loc><image:title>RigMiner</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/10/stas.png</image:loc><image:title>stas</image:title></image:image><lastmod>2017-10-13T18:51:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/09/21/rig-ek-via-rulan-drops-an-infostealer/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/steal.png</image:loc><image:title>steal</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/load.png</image:loc><image:title>load</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/rulan1.png</image:loc><image:title>rulan</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/riginfo.png</image:loc><image:title>RigInfo</image:title></image:image><lastmod>2017-09-21T13:03:48+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/09/11/rig-ek-via-rulan-drops-quant-loader-leads-to-ursnif/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/ursnif.png</image:loc><image:title>Ursnif</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/quantloader1.png</image:loc><image:title>QuantLoader</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/dreambot.png</image:loc><image:title>dreambot</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/haquant.png</image:loc><image:title>HAQuant</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/quant.png</image:loc><image:title>Quant</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/rigparams.png</image:loc><image:title>RigParams</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/rigkey2.png</image:loc><image:title>RigKey2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/rigkey1.png</image:loc><image:title>RigKey1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/rulan.png</image:loc><image:title>Rulan</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/09/quantloader.png</image:loc><image:title>QuantLoader</image:title></image:image><lastmod>2017-09-11T08:16:53+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/08/06/rig-ek-drops-bunitu-smoke-loader-andromeda-and-a-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/andromeda.png</image:loc><image:title>Andromeda</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/rigparams.png</image:loc><image:title>RigParams</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/rc4key.png</image:loc><image:title>rc4Key</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/quadrig.png</image:loc><image:title>quadrig</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/miningbot.png</image:loc><image:title>MiningBot</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/buinut.png</image:loc><image:title>Buinut</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/smokeloader.png</image:loc><image:title>Smokeloader</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/tds.png</image:loc><image:title>TDS</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/robos.png</image:loc><image:title>Robos</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/rulan.png</image:loc><image:title>Rulan</image:title></image:image><lastmod>2017-08-18T19:59:28+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/08/03/rig-ek-via-malvertising-drops-a-trojaninfostealer/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/5888.png</image:loc><image:title>5888</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/godmode.png</image:loc><image:title>Godmode</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/params.png</image:loc><image:title>Params</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/rigtrojan.png</image:loc><image:title>RigTrojan</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/growing.png</image:loc><image:title>Growing</image:title></image:image><lastmod>2017-08-03T01:07:49+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/08/01/rig-ek-via-javascript-re-director-drops-urlzone-trojan-banker/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/rigurlzone.png</image:loc><image:title>RigUrlZone</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/refreshtoco.png</image:loc><image:title>Refreshtoco</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/redirector.png</image:loc><image:title>redirector</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/302.png</image:loc><image:title>302</image:title></image:image><lastmod>2017-08-01T12:15:45+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/08/01/magnitude-ek-xml-package-and-changes/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/obfus.png</image:loc><image:title>obfus</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/flashfile.png</image:loc><image:title>FlashFile</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/landingpage.png</image:loc><image:title>landingpage</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/xml.png</image:loc><image:title>XML</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/magnigate2.png</image:loc><image:title>Magnigate2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/magnigate1.png</image:loc><image:title>Magnigate1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/letsvape.png</image:loc><image:title>letsvape</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/letsvape2.png</image:loc><image:title>letsvape2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/magnituderender.png</image:loc><image:title>MagnitudeRender</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/08/magnitudepackage.png</image:loc><image:title>MagnitudePackage</image:title></image:image><lastmod>2017-08-01T07:57:14+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/07/31/three-rig-ek-campaigns/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/rulan.png</image:loc><image:title>Rulan</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/hookads2.png</image:loc><image:title>Hookads2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/hookads1.png</image:loc><image:title>Hookads1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/bunitu280717.png</image:loc><image:title>Bunitu280717</image:title></image:image><lastmod>2017-07-31T15:36:10+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/07/16/rig-ek-via-malvertising-drops-panda-banker/</loc><lastmod>2017-07-16T15:49:30+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/07/14/rig-ek-delivers-kronos-banker/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/kronoscnc.png</image:loc><image:title>kronosCnC</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/tripleframe.png</image:loc><image:title>tripleFrame</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/kronos.png</image:loc><image:title>Kronos</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/functions.png</image:loc><image:title>functions</image:title></image:image><lastmod>2017-07-14T02:18:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/07/04/magnitude-ek-drops-cerber-scriplet-changed-to-bmp/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/scriptletdecode.png</image:loc><image:title>ScriptletDecode</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/scripletobfs.png</image:loc><image:title>ScripletObfs</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/magprocesses.png</image:loc><image:title>MagProcesses</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/scripletcall.png</image:loc><image:title>ScripletCall</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/07/magnitudebmp.png</image:loc><image:title>MagnitudeBMP</image:title></image:image><lastmod>2017-07-04T01:56:10+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/28/magnitude-ek-drops-cbrb-cerber-ransomware/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/doublelanding.png</image:loc><image:title>DoubleLanding</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/processes.png</image:loc><image:title>processes</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/magnitudeek28.png</image:loc><image:title>MagnitudeEK28</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/cerberpic.png</image:loc><image:title>cerberpic</image:title></image:image><lastmod>2017-06-28T01:47:09+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/24/rig-magnitude-1000-follower-post/</loc><lastmod>2017-06-24T15:46:39+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/22/rig-ek-via-js-redirector-leads-to-pushdo-dropping-cutwail/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/violentposts.png</image:loc><image:title>violentposts</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/smtpspam.png</image:loc><image:title>SMTPspam</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/harmless.png</image:loc><image:title>Harmless</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/adultsite.png</image:loc><image:title>adultsite</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/rigcutwail.png</image:loc><image:title>RigCutwail</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/startup.png</image:loc><image:title>startup</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/pushdo.png</image:loc><image:title>Pushdo</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/post.png</image:loc><image:title>POST</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/frametorig.png</image:loc><image:title>FrameToRig</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/jsredirector.png</image:loc><image:title>JsRedirector</image:title></image:image><lastmod>2017-06-22T23:17:21+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/16/four-rig-ek-flows-from-malvertising-bunitu-chthonic/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/indexz-2.png</image:loc><image:title>IndexZ-2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/indexz.png</image:loc><image:title>IndexZ</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/small.png</image:loc><image:title>small</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/302malvert.png</image:loc><image:title>302Malvert</image:title></image:image><lastmod>2017-06-16T23:49:00+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/14/rig-ek-via-malvertising-drops-dreambot/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/popunderreturn.png</image:loc><image:title>popunderreturn</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/rigurlparams.png</image:loc><image:title>rigurlparams</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/dreambotactions2.png</image:loc><image:title>dreambotactions2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/popunder3.png</image:loc><image:title>popunder</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/popunder2.png</image:loc><image:title>popunder</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/adbanner1.png</image:loc><image:title>adbanner</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/dreambot1.png</image:loc><image:title>dreambot</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/dreambottraffic.png</image:loc><image:title>dreambottraffic</image:title></image:image><lastmod>2017-06-14T12:21:40+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/12/rig-ek-via-malvertising-drops-zloader-and-chthonic/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/fakeflash.png</image:loc><image:title>FakeFlash</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/chtonic1.png</image:loc><image:title>Chtonic1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/zloader1.png</image:loc><image:title>Zloader1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/chth2.png</image:loc><image:title>Chth2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/vtpic.png</image:loc><image:title>VTPic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/chtonicpic.png</image:loc><image:title>ChtonicPic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/dcdcy96xcaeyez2.jpg</image:loc><image:title>DCDcY96XcAEyez2</image:title></image:image><lastmod>2017-06-12T16:05:05+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/07/rig-ek-via-fake-eve-online-website-drops-bunitu/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/frametomal.png</image:loc><image:title>frametomal</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/smallgate.png</image:loc><image:title>smallgate</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/roughted2.png</image:loc><image:title>roughted</image:title></image:image><lastmod>2017-06-07T12:00:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/go-back/</loc><lastmod>2017-06-06T17:17:39+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://zerophagemalware.com/2017/06/06/rig-ek-via-rough-ted-delivers-chthonic/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/zeuscnc2.png</image:loc><image:title>zeuscnc2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/rigflow.png</image:loc><image:title>rigflow</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/zeuscnc.png</image:loc><image:title>zeuscnc</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/strings.png</image:loc><image:title>strings</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/roughted1.png</image:loc><image:title>roughted</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/httpequiv.png</image:loc><image:title>httpequiv</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/06/gergeggr.png</image:loc><image:title>gergeggr</image:title></image:image><lastmod>2017-06-06T13:04:31+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/06/05/rig-ek-via-roughted-drops-a-miner/</loc><lastmod>2017-06-05T11:03:05+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/31/magnitude-ek-via-roughted-drops-cerber-ransomware/</loc><lastmod>2017-05-31T09:09:01+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/30/rig-ek-via-roughted-malvertising-drops-kovter/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/exerpt.png</image:loc><image:title>Exerpt</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/prelanding1.png</image:loc><image:title>prelanding</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/hugescript.png</image:loc><image:title>HugeScript</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/iframescript.png</image:loc><image:title>IframeScript</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/roughtedfirst.png</image:loc><image:title>RoughTedFirst</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigroughtedkovter.png</image:loc><image:title>RigRoughTedKovter</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/roughted.png</image:loc><image:title>RoughTed</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/compromisedsite.png</image:loc><image:title>compromisedSite</image:title></image:image><lastmod>2017-05-30T22:16:57+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/25/magnitude-ek-via-malvertising-delivers-cerber-ransomware/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/damtfqawsaif4t1.jpg</image:loc><image:title>damtfqawsaif4t1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/scripletdeobs.png</image:loc><image:title>ScripletDeobs</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/cerberbeef.png</image:loc><image:title>CerberBeef</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/scriptlet.png</image:loc><image:title>Scriptlet</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/240517magnitudecerber.png</image:loc><image:title>240517MagnitudeCerber</image:title></image:image><lastmod>2017-05-25T16:49:22+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/19/rig-ek-via-tds-drops-smoke-loader-leads-to-teamviewer/</loc><lastmod>2017-05-19T16:37:10+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/17/magnitude-ek-via-malvertising-drops-cerber-ransomware/</loc><lastmod>2017-05-17T13:51:33+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/15/rig-ek-drops-pony-leads-to-philadelphia-ransomware/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/ponybadge.png</image:loc><image:title>PonyBadge</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/pony.png</image:loc><image:title>Pony</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/badge.png</image:loc><image:title>badge</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/locked.png</image:loc><image:title>Locked</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/noisy.png</image:loc><image:title>noisy</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigponyransom.png</image:loc><image:title>RigPonyRansom</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/ransom.png</image:loc><image:title>ransom</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/ransomnote.png</image:loc><image:title>RansomNote</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/dropped.png</image:loc><image:title>Dropped</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/hehenuclear.png</image:loc><image:title>Hehenuclear</image:title></image:image><lastmod>2017-05-15T00:44:28+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/14/rig-ek-delivers-chthonic/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/capabilities.png</image:loc><image:title>Capabilities</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/comcnc.png</image:loc><image:title>comcnc</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/prelanding.png</image:loc><image:title>PreLanding</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigchthonic.png</image:loc><image:title>RigChthonic</image:title></image:image><lastmod>2017-05-14T13:05:30+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/12/rig-ek-drops-bunitu-proxy-trojan/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/dns.png</image:loc><image:title>DNS</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigbunitu.png</image:loc><image:title>RigBunitu</image:title></image:image><lastmod>2017-05-14T14:15:29+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/05/09/rig-ek-drops-failed-payload-new-params/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/smallgate.png</image:loc><image:title>SmallGate</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/cmdaction.png</image:loc><image:title>cmdaction</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/newparams.png</image:loc><image:title>NewParams</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigekfailed1.png</image:loc><image:title>RigEKFailed</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/05/rigekfailed.png</image:loc><image:title>RigEKFailed</image:title></image:image><lastmod>2017-05-09T02:19:51+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/27/rig-ek-via-decimal-redirect-drops-smoke-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/iframetorigandgif.png</image:loc><image:title>iframetorigandgif</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/decimalredirect.png</image:loc><image:title>DecimalRedirect</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/35.gif</image:loc><image:title>35</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/rigsmoke1.png</image:loc><image:title>Rigsmoke</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/rigsmoke.png</image:loc><image:title>Rigsmoke</image:title></image:image><lastmod>2017-04-27T17:13:14+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/28/rig-ek-via-malvertising-delivers-bunitu/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/bunitu270217.png</image:loc><image:title>bunitu270217</image:title></image:image><lastmod>2017-04-27T00:48:03+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/27/multiple-magnitude-ek-drops-cerber-ransomware-samples/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/cerberpuzzle.png</image:loc><image:title>CerberPuzzle</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/language.png</image:loc><image:title>Language</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/cerberpic1.png</image:loc><image:title>CerberPic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/cerbericon.png</image:loc><image:title>CerberIcon</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/cerberdecrypt.png</image:loc><image:title>CerberDecrypt</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/mag3.png</image:loc><image:title>Mag3</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/mag2.png</image:loc><image:title>Mag2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/mag1.png</image:loc><image:title>Mag1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/26magcerber.png</image:loc><image:title>26MagCerber</image:title></image:image><lastmod>2017-04-27T14:56:52+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/21/magnitude-ek-delivers-cerber/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/cerberpic.png</image:loc><image:title>CerberPic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payloadexecutes.png</image:loc><image:title>PayloadExecutes</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/flashtopayload.png</image:loc><image:title>FlashToPayload</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/magnitudeekcerber.png</image:loc><image:title>MagnitudeEKCerber</image:title></image:image><lastmod>2017-04-21T02:07:02+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/20/magnitude-ek-urls-from-14-20-april/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/scriplet.png</image:loc><image:title>scriplet</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/200417magnitudeek1.png</image:loc><image:title>200417MagnitudeEK</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/shellcode.png</image:loc><image:title>Shellcode</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payloadpic.png</image:loc><image:title>payloadpic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/magnitudeflash.png</image:loc><image:title>MagnitudeFlash</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/landingpage2.png</image:loc><image:title>LandingPage2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/2ndlanding.png</image:loc><image:title>2ndLanding</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/deobfuscated.png</image:loc><image:title>Deobfuscated</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/landingpage.png</image:loc><image:title>LandingPAge</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/gatetoek.png</image:loc><image:title>GateToEK</image:title></image:image><lastmod>2017-04-27T18:31:17+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/14/terror-ek-via-malvertising-drops-smoke-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payload.png</image:loc><image:title>payload</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payloadcall2.png</image:loc><image:title>payloadcall</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payloadcall1.png</image:loc><image:title>payloadcall</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/calltoflash.png</image:loc><image:title>CalltoFlash</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/payloadcall.png</image:loc><image:title>payloadcall</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/iframe.png</image:loc><image:title>iframe</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/pw2.png</image:loc><image:title>PW2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/pw.png</image:loc><image:title>PW</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/smokeparty.png</image:loc><image:title>SmokeParty</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/130417-terrorek.png</image:loc><image:title>130417-TerrorEK</image:title></image:image><lastmod>2017-04-14T11:11:32+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/11/unknown-ek-from-magnitude-ek-gate-drops-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/executing.png</image:loc><image:title>executing</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/document.png</image:loc><image:title>document</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/exploit1.png</image:loc><image:title>exploit1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/gate3.png</image:loc><image:title>Gate3</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/gate2.png</image:loc><image:title>Gate2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/gate1.png</image:loc><image:title>Gate1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/magnitudeek1.png</image:loc><image:title>MagnitudeEK</image:title></image:image><lastmod>2017-04-11T02:31:05+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/10/rig-ek-via-malvertising-delivers-bunitu-2/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/100417-rigbunitu.png</image:loc><image:title>100417-RigBunitu</image:title></image:image><lastmod>2017-04-10T22:41:40+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/02/terror-ek-delivers-zeusvmk-i-n-s/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorekzeusvmkins1.png</image:loc><image:title>TerrorEKZeuSVMKINS</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorekkins2.png</image:loc><image:title>TerrorEKKins</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorekkins1.png</image:loc><image:title>TerrorEKKins</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorekkins.png</image:loc><image:title>TerrorEKKins</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/iframes.png</image:loc><image:title>Iframes</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorpost.png</image:loc><image:title>TerrorPost</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/terrorekzeusvmkins.png</image:loc><image:title>TerrorEKZeuSVMKINS</image:title></image:image><lastmod>2017-04-02T14:16:45+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/04/01/terror-ek-delivers-bitcoin-miner/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/04/290317terrorek.png</image:loc><image:title>290317TerrorEK</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/2013-2551.png</image:loc><image:title>2013-2551</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/20146332.png</image:loc><image:title>20146332</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/20130074.png</image:loc><image:title>20130074</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/steam.png</image:loc><image:title>Steam</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/minerd.png</image:loc><image:title>minerd</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/hybridprocess.png</image:loc><image:title>hybridprocess</image:title></image:image><lastmod>2017-04-01T16:26:42+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/29/rig-ek-delivers-smoke-loader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/landingdirect.png</image:loc><image:title>LandingDirect</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigeksmokeloader2.png</image:loc><image:title>RigEKSmokeLoader</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/smoke2.png</image:loc><image:title>Smoke2</image:title><image:caption>Smoke Loader CNC</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigold.png</image:loc><image:title>RigOld</image:title><image:caption>Old style Rig URL</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/smoke1.png</image:loc><image:title>Smoke1</image:title><image:caption>Smoke Loader connectivity check</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rig1.png</image:loc><image:title>Rig1</image:title><image:caption>Rig EK landing page</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rig2.png</image:loc><image:title>Rig2</image:title><image:caption>Downloading payload</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/gate21.png</image:loc><image:title>Gate2</image:title><image:caption>Gate 2 302 redirect</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/gate11.png</image:loc><image:title>Gate1</image:title><image:caption>Gate 1 302 redirect</image:caption></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigeksmokeloader1.png</image:loc><image:title>RigEKSmokeLoader</image:title></image:image><lastmod>2017-03-29T06:21:25+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/24/terror-ek-delivers-tofsee-spambot/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/etterror.png</image:loc><image:title>ETTerror</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/tofseeexe.png</image:loc><image:title>tofseeexe</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/landingpaget1.png</image:loc><image:title>LandingPageT1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/terrorek-tofsee.png</image:loc><image:title>TerrorEK-Tofsee</image:title></image:image><lastmod>2017-03-24T01:14:50+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/23/magnitude-ek-via-malvertising/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/landingpage2.png</image:loc><image:title>LandingPage2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/landingpage1.png</image:loc><image:title>LandingPage1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/gate2.png</image:loc><image:title>Gate2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/gate1.png</image:loc><image:title>Gate1</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/magnitudeek.png</image:loc><image:title>MagnitudeEK</image:title></image:image><lastmod>2017-03-23T23:41:00+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/20/rig-ek-delivers-bunitu-proxy-trojan/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/smallgate.png</image:loc><image:title>SmallGate</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/bunito303gate.png</image:loc><image:title>Bunito303Gate</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/bunituinfographic.png</image:loc><image:title>BunituInfoGraphic</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigekbunitu.png</image:loc><image:title>RigEKBunitu</image:title></image:image><lastmod>2017-03-20T22:43:01+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/18/rig-ek-via-malvertising-delivers-zeus-panda/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigekfailed.png</image:loc><image:title>RigEKFailed</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rig-domains.png</image:loc><image:title>Rig Domains</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigekzeuspanda.png</image:loc><image:title>RigEKZeuSPanda</image:title></image:image><lastmod>2017-03-18T16:50:44+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/13/rig-ek-via-malvertising-delivers-zeus-variant-chthonic/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/rigchthonic.png</image:loc><image:title>RigChthonic</image:title></image:image><lastmod>2017-03-14T00:12:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/08/rig-ek-delivers-august-stealer/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/stealer-9.png</image:loc><image:title>stealer-9</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/040317-rigaugust.png</image:loc><image:title>040317-RigAugust</image:title></image:image><lastmod>2017-03-09T13:26:27+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/08/sundown-ek-delivers-zeus-panda-but-c2-offline/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/070317-sundownzeuspanda.png</image:loc><image:title>070317-SundownZeuSPanda</image:title></image:image><lastmod>2017-03-08T21:43:16+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/06/sundown-ek-delivers-zloader-and-zbot/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/stego.png</image:loc><image:title>Stego</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/zbot2.png</image:loc><image:title>Zbot2</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/zbot.png</image:loc><image:title>Zbot</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/compromisedsite.png</image:loc><image:title>CompromisedSite</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/sundown030717.png</image:loc><image:title>Sundown030717</image:title></image:image><lastmod>2017-03-08T21:01:52+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/03/02/sundown-ek-delivers-failed-payload/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/techscam.png</image:loc><image:title>techscam</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/03/sundownfail.png</image:loc><image:title>sundownfail</image:title></image:image><lastmod>2017-03-02T00:46:08+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/21/rig-ek-via-malvertising-drops-unknown-dll/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/rigunkdll.png</image:loc><image:title>rigunkdll</image:title></image:image><lastmod>2017-02-21T01:06:55+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/15/rig-ek-via-malvertising-delivers-bunitu-trojan/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/bunito-extrra.png</image:loc><image:title>bunito-extrra</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/rigekbunitu1.png</image:loc><image:title>rigekbunitu</image:title></image:image><lastmod>2017-02-15T23:48:58+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/15/sundown-ek-via-malvertising-delivers-zloader/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/140217-sundownzloader.png</image:loc><image:title>140217-sundownzloader</image:title></image:image><lastmod>2017-02-15T02:31:31+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/13/rig-via-pseudodarkleech-delivers-cerber-ransomware-3/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/130217-rigcerber.png</image:loc><image:title>130217-rigcerber</image:title></image:image><lastmod>2017-02-14T19:28:42+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/02/06/rig-via-pseudodarkleech-delivers-cerber-ransomware-2/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/050217-rigcerber1.png</image:loc><image:title>050217-rigcerber</image:title></image:image><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/02/050217-rigcerber.png</image:loc><image:title>050217-rigcerber</image:title></image:image><lastmod>2017-02-06T22:16:07+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/30/rig-via-pseudodarkleech-delivers-cerber-ransomware/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/cerberba89.png</image:loc><image:title>cerberba89</image:title></image:image><lastmod>2017-01-30T03:35:57+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/23/phishing-email-company-investigations-leads-to-ursnif/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/malspamphishing.png</image:loc><image:title>malspamphishing</image:title></image:image><lastmod>2017-01-26T03:45:15+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/25/rig-v-via-pseudodarkleech-delivers-cerber-2/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/250117-rigcerber.png</image:loc><image:title>250117-rigcerber</image:title></image:image><lastmod>2017-01-25T08:00:40+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/19/rig-v-via-pseudodarkleech-delivers-cerber/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/190117rigcerber.png</image:loc><image:title>190117rigcerber</image:title></image:image><lastmod>2017-01-20T00:51:52+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/17/compromised-site-with-pseudodarkleech-rig-ek-and-cerber-ransomware-and-mobile-malware-redirect/</loc><image:image><image:loc>https://zerophagemalware.com/wp-content/uploads/2017/01/mobilemalware.png</image:loc><image:title>mobilemalware</image:title></image:image><lastmod>2017-01-20T00:51:11+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/compromised-site-with-pseudodarkleech-rig-ek-and-cerber-ransomware-and-mobile-malware-redirect/</loc><lastmod>2017-01-17T01:02:05+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://zerophagemalware.com/useful-links/</loc><lastmod>2017-01-14T22:50:22+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://zerophagemalware.com/2017/01/14/older-posts-from-twitter/</loc><lastmod>2017-01-14T22:36:27+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/2017/01/14/welcome-to-zerophage-malware/</loc><lastmod>2017-01-14T22:32:33+00:00</lastmod><changefreq>monthly</changefreq></url><url><loc>https://zerophagemalware.com/contact/</loc><lastmod>2017-01-14T22:29:22+00:00</lastmod><changefreq>weekly</changefreq><priority>0.6</priority></url><url><loc>https://zerophagemalware.com</loc><changefreq>daily</changefreq><priority>1.0</priority><lastmod>2019-07-24T11:37:24+00:00</lastmod></url></urlset>
