Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-09 #locky email phishing campaign "Documents Requested"
- Email sample:
- - sender email address is faked to be from same domain as recepient's
- - attached filename is doc(<number>).zip, new doc(<number>).zip, or Untitled(<number>).zip
- -------------------------------------------------------------------------------------------------------------
- From: "Danny"
- To: [REDACTED]
- Subject: FW:Documents Requested
- Dear [REDACTED],
- Please find attached documents as requested.
- Best Regards,
- Danny
- -------------------------------------------------------------------------------------------------------------
- Attached file "doc(3).zip" contains file <random_chars>.wsf containing a JScript downloader:
- Download sites (the actual URLs have suffix ?<random>=<random> which does not affect download):
- http://Aadreezzcinemedia.net/JHgy64HJBRd
- http://abcdraw.biz/JHgy64HJBRd
- http://adss30.net/JHgy64HJBRd
- http://allcateringservices.in/JHgy64HJBRd
- http://ativa3.tempsite.ws/JHgy64HJBRd
- http://bangbang55.com/JHgy64HJBRd
- http://clickhubli.com/JHgy64HJBRd
- http://clickroses.com/JHgy64HJBRd
- http://crazycreations.in/JHgy64HJBRd
- http://demo.hubliclick.in/JHgy64HJBRd
- http://draarun.com/JHgy64HJBRd
- http://files.mostafaahmadi.ir/JHgy64HJBRd
- http://fpspv.beep.pl/JHgy64HJBRd
- http://gift2belgaum.com/JHgy64HJBRd
- http://gunturnayeebrahminemployees.com/JHgy64HJBRd
- http://herosoft.biz/JHgy64HJBRd
- http://hostit.co.in/JHgy64HJBRd
- http://kitsgnt.com/JHgy64HJBRd
- http://mottofotograf.com/JHgy64HJBRd
- http://mysoregiftsflowers.com/JHgy64HJBRd
- http://npinfosoft.16mb.com/JHgy64HJBRd
- http://nysekolintsika.mg/JHgy64HJBRd
- http://partyeazy.com/JHgy64HJBRd
- http://platforms-root-technologies.com/JHgy64HJBRd
- http://pmlojistik.com/JHgy64HJBRd
- http://rajashekharkubasad.com/JHgy64HJBRd
- http://ratecompares.com/JHgy64HJBRd
- http://root-technologies.net/JHgy64HJBRd
- http://samssara.com/JHgy64HJBRd
- http://sasmgs.org/JHgy64HJBRd
- http://scpolytechnic.com/JHgy64HJBRd
- http://site1382371826.provisorio.ws/JHgy64HJBRd
- http://syamasahithi.com/JHgy64HJBRd
- http://synergyconnect.in/JHgy64HJBRd
- http://technometics.com/JHgy64HJBRd
- http://tranzporthub.com/JHgy64HJBRd
- http://vajrammatrimony.com/JHgy64HJBRd
- http://wamasoftware.com/JHgy64HJBRd
- http://websamrat.in/JHgy64HJBRd
- http://www.ausaf.pk/JHgy64HJBRd
- http://www.draarun.com/JHgy64HJBRd
- http://www.rajashekharkubasad.com/JHgy64HJBRd
- http://www.villakeratea.it/JHgy64HJBRd
- Malware encoded on download, SHA256 23f3f58acff330900109138918c49c4a6ae9efe3ac88f63a114a293d37e5e914, filesize 159744 bytes
- https://www.reverse.it/sample/194805c87e872aea0f2aa9ba766b009e11b6a781b7c978af6a72aac296b0cabf?environmentId=100
- https://www.reverse.it/sample/bc8c9dac84f5f3dc150219e73406137377bb35cbbe4da1702e84f51aa2db8ff4?environmentId=100
- https://www.reverse.it/sample/3832b31ed85bf48ffc57760ffe754e44ef18bc0fef956ba38b371070b05a854d?environmentId=100
- https://www.reverse.it/sample/0386060b08abaf9298302d8922aa17f804e63c74950aa2ac20cc030f24171480?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement