Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-02 #locky email phishing campaign "xxxxxgif, xxxxxtiff, xxxxxpdf"
- Email:
- ----------------------------------------------------------------------------------------------------------------------
- From: "Benny_09370@icloud.com" <Benny_09370@icloud.com>
- To: [REDACTED]
- Subject: 121181995tiff
- Date: Fri, 02 Sep 2016 02:08:49 -0700
- Attachment: 121181995.zip
- ----------------------------------------------------------------------------------------------------------------------
- - sender address is <name>_<random number>@icloud.com
- - subject is <random_number><docx|tiff|jpg|png|pdf|gif>
- - email body is empty
- - attachment name is <random_number>.zip, <random_number> matches the subject <random_number>
- - attachment contains file "<random chars>.wsf" a JScript downloader
- Download sites (actual URLs have ?<random>=<random> suffix which does not affect download)
- http://158.195.68.10/porirue
- http://209.41.183.242/cerhgsj
- http://69.61.11.216/ikpmpue
- http://abcbureautique.abc.perso.neuf.fr/yfyyiyr
- http://albertowe.cba.pl/terwquq
- http://andante-co.jp/orxovwy
- http://bajkowestokrotki.cba.pl/jsypbws
- http://cultpro.ru/lhnqtla
- http://danzig.vtrbandaancha.net/djaokpj
- http://dcqoutlet.es/vcxyssl
- http://e-gmp.home.ro/ierssce
- http://ghost-tony.com.es/bxrsksb
- http://golfteam.fr/kqlhtqe
- http://greentechdesign.ca/bswfvhl
- http://illaghettodelcircoletto.it/flkekqs
- http://imex.atspace.com/sxqtddp
- http://immobilien1000.de/igrakbo
- http://josemedina.com/tveslqt
- http://lokum1985.republika.pl/dsmggtg
- http://maxshoppppsr.biz/js/vf3gt4b4
- http://maxshoppppsr.biz/js/y54g3tr
- http://news.oboyle.ro/myeyuum
- http://olivier.coroenne.perso.sfr.fr/bskhcyg
- http://portadeenrolar.ind.br/rtaoqip
- http://postaldigitalrs.com.br/buwjobf
- http://pp4_09_10_2s.republika.pl/vifalte
- http://srxrun.nobody.jp/mjhltpo
- http://szkolagrojec.republika.pl/skdulpr
- http://tujdaehn.homepage.t-online.de/nrsojje
- http://unimet.tmhandel.com/nibttjk
- http://www.agridiving.net/dawkmoc
- http://www.alanmorgan.plus.com/yqjytxx
- http://www.alessandrocangiano.com/bnnjyle
- http://www.alpstaxi.co.jp/dueisgs
- http://www.anacuamic.com/pcoyepo
- http://www.archiviestoria.it/waotorf
- http://www.association-julescatoire.fr/vdrnlnt
- http://www.bavaria-wein.de/kyisute
- http://www.bluedizioni.com/iskorry
- http://www.caminettilcd.it/ikpjqqt
- http://www.cortesidesign.com/qfdirfh
- http://www.coseincredibili.it/gugpcpb
- http://www.courtesyweb.it/fvtuknb
- http://www.dallaglio-nordin.com/cjkgjtl
- http://www.ediazahar.com/oqyvsuh
- http://www.empolio.com/bgfxwqs
- http://www.erretisnc.it/ehujqne
- http://www.fenit.net/elckuqa
- http://www.imaginarium.home.ro/hmfbirt
- http://www.impresadeambrosis.it/bwkwpjd
- http://www.informaonline.org/qpbhrdw
- http://www.malicioso.net/ulndads
- http://www.meallservice.it/mulccfi
- http://www.motortecnica.org/vfkhqpi
- http://www.mussystems.net/rhygtpe
- http://www.saumi.jazztel.es/snyhslx
- http://www.termoalbiate.com/uwmakrm
- http://www.threshold-online.co.uk/jicxccg
- http://www.trauchgauer-weihnachtsmarkt.de/vqupuun
- http://www.valerypro.com/trmqtsy
- Malware
- - encoded on download, SHA256 4baf40fe1c7fafd89befe4f2e2bd36aefc8a4faf395631d8bac20e09e372725b, filesize 201216
- - decoded SHA256 852c79d430e401f6b57946718ca6555c328dd503b13b9cda22e481903ebe8575
- - encoded on download, SHA256 65d76a8ad5ad5817d1abc977c3b5585dc26b12be18b690637e6722811e91af8c, filesize 201728
- - decoded SHA256 72d9cbdec23f9c4f95ce8fb1217ef67c979957c58b4fb7c8fe98ac8cec62aca7
- - executed by "rundll32.exe %TEMP%\XxncrW1.dll,qwerty"
- https://www.reverse.it/sample/f4dc61df743a5fc1335c06c72fd992e8e88f34187194aae9b308d7acb2eb2fc5?environmentId=100
- https://www.reverse.it/sample/41bd08637ce358db145bfd313165c92d25428f723523e11329d1a8467b8801db?environmentId=100
- C2:
- 149.154.152.108:80/data/info.php
- 212.109.192.235:80/data/info.php
- ssvylrn.pw:80/data/info.php [91.223.180.66]
- cdxbbpngq.pw:80/data/info.php [188.120.232.55]
- qsbfwgtedexirbyoq.pw:80/data/info.php [95.211.174.92]
Add Comment
Please, Sign In to add comment