Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-05-26: #jaff email phishing campaign "Scanned Image from a Xerox WorkCentre"
- Email sample:
- ---------------------------------------------------------------------------------------------------------------
- From: "copier@[REDACTED]" <copier@[REDACTED]>
- To: [REDACTED]
- Subject: Scanned Image from a Xerox WorkCentre
- You have a received a new image from Xerox WorkCentre.
- Sent by: copier@[REDACTED]
- Number of Images: 2
- Attachment File Type: PDF
- WorkCentre Pro Location: Machine location not set
- Device Name: copier@[REDACTED]
- Attached file is scanned image in PDF format.
- Attachment: Scan_0069_1694379267.zip
- ---------------------------------------------------------------------------------------------------------------
- - Sender: (copier|scanner|xerox|canon|MFD)@<recipient's domain>
- - Subject: "Scanned Image from a Xerox WorkCentre"
- - Attachment Scan_<3-4 numbers>_<10 numbers>.zip contains file <9 numbers>.zip which contains file <9 numbers>.wsf, a JScript downloader
- Download sites (the URL contains suffix ?<random>=<random> which does not influence download):
- http://better57toiuydof.net/af/6gfh33
- http://dsopro.com/6gfh33
- http://easy2.cn/6gfh33
- http://eisenerzgrube.de/6gfh33
- http://eselink.com.my/6gfh33
- http://e-snhv.com/6gfh33
- http://fabriquekorea.com/6gfh33
- http://jinqiaonkyy.com/6gfh33
- http://orhangazitur.com/6gfh33
- http://paradigmenergycorp.com/6gfh33
- http://poltec.com.au/6gfh33
- http://praktikum-marketing.de/6gfh33
- http://pw-shop.com/6gfh33
- http://tasfirin-ustasi.net/6gfh33
- http://thanprints.com/6gfh33
- http://trade-unite.ru/6gfh33
- http://vigs.mx/6gfh33
- http://www.buchenried.de/6gfh33
- http://youtoolgrabeertorse.org/af/6gfh33
- Malware:
- - encoded on download SHA256 68c7b7d97fada3f558a54260491ffe1ce77add158f8a91c2599432f13718b807, MD5 aace687d16706b05aa49c9b7fff7572b
- - decode by XORing the file with oACQkDYkveevPExWGku00eNvCy0LSnCn
- - decoded SHA256 375ba5457b0a8e0328f38e942dc16fa07e03e2b39571392c0f10f93031158d6f, MD5 6708cc80916e838a9bbed09c91854230
- C2:
- http://comboratiogferrdto.com/a5/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement