Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- *Email sample*
- _Subject_: Final version of the report
- _Body_:
- Dear [NAME],
- Lance Davis asked me to send you the attached Word document, which contains the final version of the report.
- Please let me know if you have any trouble with the file, and please let Lance know if you have any questions about the contents of the report.
- Kind regards
- Faith Leonard
- Chief Executive Officer
- In attachment a zip archive with a javascript file.
- Javascript sample - MD5: c4b65cb100b08a3e3b366ccf7c161dc9
- VT: 1/55 - https://www.virustotal.com/en/file/3fe9169a286bcedc3c7ba1da0160dded07af0540211ed32c6144cc4435f4a42e/analysis/
- *Compromised domains (49)*:
- 3141592.ru/ wyesvj
- 4k18.com/ u69f97
- aberfoyledental.ca/ 6dil05
- abligl.com/ 8v62l4i4
- adbm.co.uk/ 1o2wejz
- angeelle.nichost.ru/ y6s1y9h
- arogyaforhealth.com/ jujg6ru
- atlantaelectronics.co.id/ quv7rcc1
- babycotsonline.com/ ph42q6ue
- barum.de/ c2blg
- beautifulhosting.com.au/ rxn80
- bilgoray.com/ vi5sfu
- bobbysinghwpg.com/ pdqcqlnr
- boranwebshop.nl/ ggc7ld
- bptec.ir/ kvk9leho
- cameramartusa.info/ xrfpm
- capitalwomanmagazine.ca/ 6k1oig
- century21keim.com/ c7xb2xy
- certifiedbanker.org/ obmv6590
- cg.wandashops.com/ evqbfwkx
- clients.seospell.co.in/ fkn67zy
- climairuk.com/ h32k491o
- climatizareonline.ro/ azkqs
- cond.gribochechki.ru/ zibni
- dentalshop4you.nl/ m22brjfz
- disneyexperience.com/ psyyhe
- elviraminkina.com/ ojyq1
- empiredeckandfence.com/ h2uppib
- euro-support.be/ rdl3n7u
- focolareostuni.it/ 0k2ren
- freesource.su/ ijugasq1
- grantica.ru/ 6hjli
- honeystays.co.za/ siu2k
- ideograph.com/ k7qfsxx
- imetinyang.za.pl/ 74hd4by5
- immoclic.o2switch.net/ styvuwti
- jd-products.nl/ xjld131
- karl-lee.se/ x23ft
- margohack.za.pl/ wkiokl
- matvil8.freehostia.com/ 64tmb1
- mycreativeprint.com/ mqib9te
- oakashandthorn.charybdis.seedboxes.cc/ f7ge4y3k
- promoresults.com.au/ gx4al
- redpower.com.au/ xlkdld
- tip.ub.ac.id/ k2e32vh
- www.centroinfantilelmolino.com/ 60wfh
- www.darkhollowcoffee.com/ oqlyd9m
- www.ellicottcitypediatrics.com/ 7d6sdl
- www.keven.site.aplus.net/ fmlonxl
- *Sampled downloaded and decoded*:
- File Name: 9oaELw13vFr7w.exe
- MD5: 4d48a039371d95e49b8ef7c4e2459946
- VT 4/56 - https://virustotal.com/en/file/e5a6828f732bea6b66c4f6d850b235f6c1f139b10f8d9f2c3760298cfd88c163/analysis/
- For this campaign the argument passed to the Locky dropper is no more 123 but 321. Credit to @siri_urz
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement