SHARE
TWEET

2016-12-15 Locky "Payment Processing Problem"

Racco42 Dec 16th, 2016 156 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2016-12-15: #locky email phishing campaign "Payment Processing Problem"
  2.  
  3. Email sample:
  4. ---------------------------------------------------------------------------------------------------------------------
  5. From: "Riley Henderson" <Henderson.Riley@clemocleckheaton.citroen.co.uk>
  6. To: [REDACTED]
  7. Subject: Payment Processing Problem
  8. Date: Thu, 15 Dec 2016 23:29:43 +0200
  9.  
  10. Dear [REDACTED],
  11.  
  12. We have to inform you that a problem occured when processing your last payment (code: 3618289-M, $747.$63).
  13. The receipt is in the attachment. Please study it and contact us.
  14.  
  15. -
  16. King Regards,
  17. Riley Henderson
  18.  
  19. Attachment: MPay3618289.zip -> ~_U4DQW_~.js
  20. ---------------------------------------------------------------------------------------------------------------------
  21. - sender varies between emails
  22. - subject is "Payment Processing Problem"
  23. - attached file "MPay<7 digits>.zip" contains file "~_<5-7 uppercase chars and digits>_~.js", a JScript downloader
  24.  
  25. Download sites:
  26. http://028cdxyk.com/mltxgc1
  27. http://1688daigou.com/csuix
  28. http://2lazy4u.de/ca4yq
  29. http://adv-tech.ru/7p1jia
  30. http://allan.multimediedesignerskive.dk/pohtr8mwl
  31. http://amaniinitiative.org/ubaupn
  32. http://antalyalaraklima.com/4qdytc9
  33. http://artcoredesign.com/9ihg6by
  34. http://atelier-coccolino.com/cvpphnaf7o
  35. http://auto-zakaz.com.ua/phwcg
  36. http://bantiki.me/hzzgidch
  37. http://bikebrowse.com/qap3je2
  38. http://blueprint-dsg.com/dtr22
  39. http://bvntech.com/amrwwxei
  40. http://chonamyoung.com/9vsdld
  41. http://cprsim.com/h9o3msx
  42. http://dealspari.com/r2jvx5h6kc
  43. http://demo.ahost5.ru/dhvzqqbo
  44. http://demo.pornuha4you.com/lba7ajvti
  45. http://deutsch.awardspace.info/0zetkhmp
  46. http://dicksmacker.com/qq4ctnrgc
  47. http://dryerventexpress.com/pnpafot9g
  48. http://elevationmusic.de/6gcg6
  49. http://e-studiz.com/hn0hl7i
  50. http://formatwerbung.de/axxlilgd
  51. http://gieslerdavies.com/cjhwnit
  52. http://goldenarms.myjino.ru/3wn40qkg
  53. http://happyfeet.de/7rebctpqn5
  54. http://hho68.com/hbowe
  55. http://honestflooring.com/85i95u6vd
  56. http://houssiere.daniel.formations-web.alsace/npqddd8b
  57. http://infinitecorp.ca/to7jp7
  58. http://kawagebook.com/5cbwdd5hap
  59. http://kayamuh.sarf.com.tr/nou0chc
  60. http://ledticket.com/pbmcdnx5rj
  61. http://lucapotenziani.com/zjtguxf
  62. http://mainlinecarriers.co.tz/ycj7o
  63. http://martawyczynska.com/ilfvn
  64. http://mbdvacations.com/ou8kkem
  65. http://movewithgrace.ca/r8omwc
  66. http://obccllc.com/tze5um3hh
  67. http://old.strommarnas.se/yazezuw7og
  68. http://seven-cards.com/xe2llygi
  69. http://spikaflora.ru/zyubd6mlb
  70. http://store.elixe.net/jltuvjpcsh
  71. http://test1.zrise.top/isk90e
  72. http://testlife.ruyigou.com/pv2ryezg7
  73. http://theexcelconsultant.com/vp9u7tpa
  74. http://thezenatwork.com/yd2c49vg0
  75. http://topstoneisland.com/ud4jqd
  76. http://tunca.bel.tr/uo3jnqkgxn
  77. http://ustadhanif.com/q0w93lkrvp
  78. http://www.boldrini.org.br/csneth51
  79. http://www.chocolaterie-servant.com/1l38y2p
  80. http://www.englishworld.it/w6ynmr
  81. http://www.kottalgenealogy.com/vkwf5rll0s
  82. http://www.sapol.it/ou8e1ftep
  83. http://zapotech.com/sqagj4
  84. http://zhongguanjiaoshi.com/mklu7
  85.  
  86. Malware:
  87. - encoded on download
  88. 83b18bfa0f0ea4c91e06c7dededf0ffe1e47d03f96e5a443fd76af0a0ee2eab6  http___028cdxyk.com_mltxgc1
  89. a1e9a3acab9b88f1b1b0163803447e2c88d7437b3fdfd02d5585c2de51957702  http___1688daigou.com_csuix
  90. e5df90547f15ce224a4e393c70b19c01882e95a412f067441f047747bf41e1d1  http___2lazy4u.de_ca4yq
  91. 42ea0e10cf79a0723e67a0be8621c308306f5a2818589928cbf9f8b3997da946  http___allan.multimediedesignerskive.dk_pohtr8mwl
  92. 87fad71988400eefc2139cc3a3616fa21f683290b73247bc2b9ba37bba54e636  http___amaniinitiative.org_ubaupn
  93. 5740c7dc9879c655b313822517b709af884b7135a0696c0687b2c0874347d12b  http___antalyalaraklima.com_4qdytc9
  94. 99fbd9400b3d252f44384e4adda3d4816833d2d98b6e995097b99adf00bdf243  http___artcoredesign.com_9ihg6by
  95. 2cdacad8b8317da8e19021cd1e0dd04e7e15877d995df6cfcd2aad9c0af24e60  http___atelier-coccolino.com_cvpphnaf7o
  96. f075b2cc9c2e44b06d8e0a5b3d30d0250d5f636c1683eb5275a87ab9ed35b2bc  http___auto-zakaz.com.ua_phwcg
  97. 94012941c43343097974d97763cff4356845607fdd468d84835c2b022f24b1ee  http___bantiki.me_hzzgidch
  98. b1585999de7d1c355b4f24022dbdc35e3e4e29384b1b412cae5e80b2d0a2a83d  http___bikebrowse.com_qap3je2
  99. 5cd6f30355aa124ed87780c2dd9b3e9ccc125142a78c55da720fa8a598c47dbf  http___blueprint-dsg.com_dtr22
  100. ab3d42819f39353b6eb45ce12e99d614caaa19efbf9900ab6720801167d49520  http___bvntech.com_amrwwxei
  101. c8e81da73db72dd0e64901ab14b57b5f0e68c278d4affc503553e1cdd943eda3  http___chonamyoung.com_9vsdld
  102. 1a221f5f2d6f70f4b425e21556c2020929407d3f139db91e19521a9b8bbd28d0  http___cprsim.com_h9o3msx
  103. c46c9072a3933dca5458db108873bdd64f3a1898d77ae4b52ef3c0c5ca8a3fd5  http___dealspari.com_r2jvx5h6kc
  104. 44a7c015e4873b23a31cbfb7fb9476d0df91e9d3cc3f7d5b855c87bbe8d084ef  http___demo.ahost5.ru_dhvzqqbo
  105. 4cc4b50d6c0ec3772cab4ea5a59cb0a3d5c36631c5e7b52951e1ccc6c2651318  http___demo.pornuha4you.com_lba7ajvti [1]
  106. f3df4795deb7a7f36b79749dda7c97fd17ee4f6c976fb7c590eff1d344662ac9  http___dicksmacker.com_qq4ctnrgc
  107. 268ea8e8ff6fd6668db644cec2f195f58e24af29b4d34f196851ce5e40640b57  http___dryerventexpress.com_pnpafot9g
  108. 7ff08628dda6d07eb3d9f6aee9e0fd105d4df63fc0e704c140cc42750af63181  http___elevationmusic.de_6gcg6
  109. d1b12518cdabcd6ae0736e96229b08297265ade16fe9a7e97b2061da300fc33a  http___e-studiz.com_hn0hl7i
  110. ca023fab08bea5f800824e4804372276c2822676e0dd654305d43bb4e7fa1f4f  http___formatwerbung.de_axxlilgd
  111. 4b37957a5d57e4ca6f6a5491332c9f10e521e499140c103c11d24bf5b62c725a  http___gieslerdavies.com_cjhwnit
  112. dc72d1f14d6fc34234e173cc003738f74b9deacda057a2c99f28f99f9c754d03  http___goldenarms.myjino.ru_3wn40qkg
  113. ffd00735d289a3f92f2286fa5f4b2b861313617b1dc813ca039d151ca049ce88  http___happyfeet.de_7rebctpqn5
  114. c6b1948217918aa929e0920ed4a0546c71e900ef707d480183f2846170adaba9  http___hho68.com_hbowe
  115. 9521dbca9670112fa588144fa5a4822293379cac99bb6a5c935df950d6971415  http___honestflooring.com_85i95u6vd
  116. 680ae74073a352a74bf87d314f4704927ec418a29fe8dd635cba28796cbf8294  http___houssiere.daniel.formations-web.alsace_npqddd8b
  117. d44de2ea0d1333f4226ff49234fb8b2e151ee49afb94cb6fa0993920139a0360  http___infinitecorp.ca_to7jp7
  118. 9d527a9c9e64c1bf23b5e66a0f414026ff4c77ef3565c3dbcf0ece9a92cea77a  http___kawagebook.com_5cbwdd5hap [2]
  119. 3abc8bc9e5d8c05786b220f47d72fd75b8c752336381d25b9b8c29dafd119992  http___kayamuh.sarf.com.tr_nou0chc [5]
  120. a95a109274b8528e758ff4fe0f4cc39c514e80c070d35115f1db0e9c27a89a20  http___ledticket.com_pbmcdnx5rj
  121. 26bd8f6888d688624c7c4b97a388b0c96c6318e0484a9dfb499c086434213513  http___lucapotenziani.com_zjtguxf
  122. b2bd25d9a525245049b08a08e58c315e96ca149dc8c8b32a599eddb62941465d  http___mainlinecarriers.co.tz_ycj7o
  123. c7afc0dab52159ce2ddcb182fc568875753287ab0eb84ce10d060fb29ed6c43d  http___martawyczynska.com_ilfvn
  124. 5d6468fb720fe48304d1ed0a39e3696193a96d44c2b58ff0a08e7493ca0fc175  http___mbdvacations.com_ou8kkem
  125. 7d49073e0fd3db7352e87b0ec905523840b9c6bf3917da3f8235fa797fba1056  http___movewithgrace.ca_r8omwc
  126. 9fa9ac0113a2e426ae27e0c260cb6700f179296513fdea1bbe7a4ce739008184  http___obccllc.com_tze5um3hh
  127. 4d63973d9c1a59c932e8706083c675bdea47c3c0151cdf0625c531c722565f60  http___old.strommarnas.se_yazezuw7og
  128. 5b827205964cebca51258d135dc99bc2adc5c429c9a165cb387623eca867dcb3  http___seven-cards.com_xe2llygi
  129. 7a000428f7b00040799906832759dd4a2845435bf38c057eff8b966dab825c10  http___spikaflora.ru_zyubd6mlb
  130. 154459b5c0f29ca104d9d212992764bb284d5cf3f1c9bec525b4ec8ff1a949a8  http___store.elixe.net_jltuvjpcsh
  131. c87f1a31c7309760b7063ce94df46e29bb1e4b1ca5ed47e27a42f48710107e3f  http___test1.zrise.top_isk90e [4]
  132. 6b9bde2a9a64f5f4682fbe4164221c7f4dea5b85d1c065ef058c2e81965254e0  http___testlife.ruyigou.com_pv2ryezg7
  133. a672a78794b972583ac80f99e8541e67e32cc5c3fefc891c40ba62d6495edb3c  http___theexcelconsultant.com_vp9u7tpa
  134. d3ddaf001106c70c1b57c6f3147289c65a4340ca99f6490e85fa1657de1a188c  http___thezenatwork.com_yd2c49vg0
  135. 5b28f7104d734cb2f978fc0eca19afc77e085af0aae270ff9b6c1132f81117e8  http___topstoneisland.com_ud4jqd
  136. 58c243c30868f5487f7cc74713fb8d91833cbdd3fe35deb2a5e46e60aecae734  http___tunca.bel.tr_uo3jnqkgxn [3]
  137. c0fcad199eeaec7779a8bace15a194df91c054bc1331ed0905f590ebeaad6f60  http___ustadhanif.com_q0w93lkrvp
  138. cea33796e86f5fda0caac1d078085f05b9d02df7acdb385e701d1e577287ce8c  http___www.boldrini.org.br_csneth51
  139. b383e22faef47aa78cb2fb23050893b5c020670d8c9257b0e85ddca87262070a  http___www.chocolaterie-servant.com_1l38y2p
  140. 96cfd93d259f3bc06ead97a0a62bdce6d3dc4607b96a374505c7cb7ab0663a20  http___www.englishworld.it_w6ynmr
  141. b274f2e8e2abf4d0571f1f8736c46e584b49894ef6b25816aeb6cfbc62c18e8d  http___www.kottalgenealogy.com_vkwf5rll0s
  142. 0dbd5e95de3d1923cae17335d0b0035790ea7328762b741c60e8f23cca3630c8  http___www.sapol.it_ou8e1ftep
  143. 0dafd7df93c6db429329c971e91b8050e67a6aca1c8cec86ced2714b28bc9f45  http___zapotech.com_sqagj4
  144. 64fd485e3ab0e892703066c4d479c5f6709d48214fc8c0070743936394cb7a6f  http___zhongguanjiaoshi.com_mklu7
  145. - decoded
  146. 1a8c0a8648ee8bb5822769e160e2d607614803c097c8884a7b144ccf00f780c4 [1]
  147. 18af5b240dec53a77e95982e39b08b6235bc235eb1e8267e2a93992eb66a1b19 [2]
  148. f46923e5d6c9f23996b183fa5870a0daf0840ea06d4506abcd01d9ccf450f19c [3]
  149. 40614a8db9f111ec44c68f14e674f3e19c6da97f2844f249af563b4ad96a24eb [4]
  150. 01d3eb86fdfc9f90be328cae3bc37aaf97b568f569626db1a3b4a1830662dbad [5]
  151. - executed by "rundll32.exe %TEMP%\<filename>.ZK,0QaQzdZN8Pft5YPfVEdEYu"
  152. - samples
  153. https://www.virustotal.com/file/1a8c0a8648ee8bb5822769e160e2d607614803c097c8884a7b144ccf00f780c4/analysis/1481887825/ [1]
  154. https://www.virustotal.com/file/18af5b240dec53a77e95982e39b08b6235bc235eb1e8267e2a93992eb66a1b19/analysis/1481887832/ [2]
  155. https://www.virustotal.com/file/f46923e5d6c9f23996b183fa5870a0daf0840ea06d4506abcd01d9ccf450f19c/analysis/1481887847/ [3]
  156. https://www.virustotal.com/file/40614a8db9f111ec44c68f14e674f3e19c6da97f2844f249af563b4ad96a24eb/analysis/1481887855/ [4]
  157. https://www.virustotal.com/file/01d3eb86fdfc9f90be328cae3bc37aaf97b568f569626db1a3b4a1830662dbad/analysis/1481887864/ [5]
  158.  
  159. C2:
  160. POST http://178.209.51.223/checkupdate
  161. POST http://185.129.148.56/checkupdate
  162. POST http://37.235.50.119/checkupdate
RAW Paste Data
Top