Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-23: #locky email phishing campaign "Attention required"
- Email sample:
- -------------------------------------------------------------------------------------------------------
- From: "Jerrold Woodward" <Woodward.Jerrold@airtel.in>
- To: [REDACTED]
- Subject: Attention Required
- Date: Thu, 24 Nov 2016 00:23:12 +0530
- Dear [REDACTED], our HR Department told us they haven't received the receipt you'd promised to send them.
- Fines may apply from the third party. We are sending you the details in the attachment.
- Please check it out when possible.
- Attachment: receipt_[REDACTED].zip -> QKB5D2772I3H3A7N.js
- -------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Attention Required"
- - attached file "receipt_<recipient name>.zip" contains file "<random upcase letters and digits>.js", a JScript downloader
- Download sites:
- http://4006600592.com/rqk0umu
- http://asrcargo.ru/tk3na
- http://chuzhang.net/e9ji7qa0
- http://dhmodel.cz/gvkwiz0ht
- http://focovi.cl/7trtuveg
- http://frivill.hu/7g2kjrr
- http://fu-k.jp/cmklw
- http://gadgetdealz.net/pyq5v2rp
- http://gigabothosting.com/kiltoonxqa
- http://giochasach.com/gagqzjjnwe
- http://golden-bereg.ru/dx1ltd
- http://gold-or.ca/ap7yazjzlq
- http://gpsfiles.nl/lywk0py
- http://gpstrackerbali.com/fhhlgyh
- http://grafian.pl/jaqn2ty
- http://greentic.univcasa.ma/alzsxurzq
- http://gremr.ma/hj4xku01
- http://happyrushop.com/it1e5eav7c
- http://hbmyzn.net/bbjnaw
- http://heatsavingsystems.com/qvdson
- http://helfter.fr/m7ud5qsmd
- http://helpcomm.com/pfw9co
- http://highlandsolar.ca/hlhc8jpj5y
- http://hightradingfrequency.com/ehn4guw6
- http://h-miyoshi.ed.jp/eggteyujbx
- http://interprofil.no/imjsj7gh0
- http://irinka.ru/vrsoiw7rw
- http://islamhizmeti.com/4rn5re
- http://i-solutions.cz/wdkdfg
- http://ivocal.fr/tydqws08pe
- http://iwebsdns.com/k0ais
- http://janzwolinski.freehost.pl/v8xnbq
- http://joelbodhi.com/pr1qz
- http://joelbodhi.com/qalnt4t
- http://joelbodhi.com/r94yyaty
- http://joelbodhi.com/srcdv0jg
- http://kleansys.com/y7oragomg
- http://kolumbia.free.bg/trbwdtze
- http://lecitron.org/rozculcvba
- http://leliunion.net/e9nw7
- http://leliunion.net/jhczf
- http://leliunion.net/kwnlmbgrv6
- http://leliunion.net/vt2dyzq
- http://markscheffel.de/wqkgiuama
- http://masterimob.ro/wbxglxsh
- http://materlux.ru/qwn5gh
- http://mdk-wear.ru/zwd98vmv
- http://meshok.com.ua/vfaolaevk
- http://mokinukai.lt/x4szqe
- http://monster-high.com.ua/tah7tzqdfq
- http://mufengzhai.com/yfnglx2
- http://muricreklamcilik.com/6qycx
- http://musicrecruiting.com/xjlecd5ju
- http://mytourbid.com/5c32pzh
- http://naruby.kvalitne.cz/t7h9qce6h
- http://nicputeec.com/6rm6xf
- http://noisecontrols.com/4nqceemivy
- http://obsidian.cl/3zttsnxknq
- http://oimeferio.net/glotrsefkp
- http://oimeferio.net/sl60vc
- http://oimeferio.net/u25orc
- http://oimeferio.net/yjibxujt
- http://ooomaksim.ru/591bwwbcu
- http://orantpamir.net/el3w488r9
- http://orantpamir.net/lyzj9ja1uh
- http://orantpamir.net/om1twg
- http://orantpamir.net/rtss2coyh
- http://orthoskin.com/1e4mdliv
- http://paddamar.net/0k0n5zjze
- http://paddamar.net/gqmfsfvg
- http://paddamar.net/irz4h
- http://paddamar.net/w3l68g
- http://panificadoraavenida.com/5ren2ksdu1
- http://peruincoming.com/2asklonmy
- http://rentalpark.com.ar/1useo
- http://vikingradom.freehost.pl/jizvw5rg0u
- http://wilson.ro/gghar9s
- Malware:
- - encoded on download:
- 6a3caf52db3988c9b338770d24fc8b148754d61fdee687480975d4c292999501 http___4006600592.com_rqk0umu
- 85ba230858a60558e7579b48c33e3d0058a43b85516dbecadeb432edcb1fcdd1 http___asrcargo.ru_tk3na [2]
- 2be67e326ca41f85fcd0370ad7e8e84f0eaad3fd94be8f23322705ab940e0002 http___chuzhang.net_e9ji7qa0
- de3442144d9c2888e3c2ea936c1a007491c56981c671706117baaa499693d1a2 http___dhmodel.cz_gvkwiz0ht
- e018fe0973a93d7e73df096a08d0434be9d333e928b5b2036288241dddf61f55 http___frivill.hu_7g2kjrr
- 17baaf09266604bc50ae832fcb6e68202a344721b7b26cad08c4717e3331af62 http___fu-k.jp_cmklw
- e36c316668af7b2fbf4f3b2e8bcdef7c871559f5330ecd6b9889dd6f3aa03df8 http___gadgetdealz.net_pyq5v2rp
- 334e2faf205ae3e368b2f62b9e111f197cb240f2fedc0d6ead4b87afe3a4b4e2 http___gigabothosting.com_kiltoonxqa
- 6f411838276f97895ef5fe53be094163066d22fa6f45964089bc63c2e678bd6d http___giochasach.com_gagqzjjnwe
- 14685c260e52c6e60ea9a13bd0d5a418d3308a670478d456390f0b5e73d9b665 http___golden-bereg.ru_dx1ltd
- 3e6a365a7722962726e210173bef46d48222b1a545d818abcb5b08ef7c9f8607 http___gold-or.ca_ap7yazjzlq
- 5f0cb614fa1ac4f724f6f0599f767b68c40ba1274cd26b2e6a3944e8beaebbd1 http___gpsfiles.nl_lywk0py [4]
- 8a40092c2028fb9297f7219be1ea2800d470dd2b4e35c3325c7c7b1699215c4c http___gpstrackerbali.com_fhhlgyh
- 9086490ed27e837653c12fa27986bebc55ac853b8170b5234c6ba7d6b206c940 http___grafian.pl_jaqn2ty
- cc862d695280ee72ecf6d8a7482dfdc3c77ebd5723762284b9b0158cb1f0437e http___greentic.univcasa.ma_alzsxurzq
- 0e3a8edf055dfeb6061e5254d4ac0c00c99aa8cffcee1848b4ab1d5e2c642e94 http___gremr.ma_hj4xku01
- 47205c2faf771eefec043bb40d3c6f6827ba2142eca72c6c7f1e37b1804572cc http___happyrushop.com_it1e5eav7c
- 8517c7f95dccb71551671f6f05b1d2f8308abf3a1d42a8387489dafa64dc2082 http___hbmyzn.net_bbjnaw
- e89c5e4cc5f7f879a92bad328b140d7d60b6ca58aaf0e6d7e7626e5b81dcfd63 http___heatsavingsystems.com_qvdson
- 2fa7a0182eddc4e65ae05344bf9b74ad71664fb0fea695497aced5823a46a8e2 http___helfter.fr_m7ud5qsmd
- 656152d8c927126f956db1b33c7c227d39457fd1c45420e234fa1c44227e97a9 http___helpcomm.com_pfw9co
- 90d4f681774542377bd4cb7d8ae5dfa8a520995342b5d1397e74635ba8d5562a http___highlandsolar.ca_hlhc8jpj5y
- 27b0e0a71f1b6b825fb941e61b570a1633d89ac56678d09eee34f21469cb23ad http___hightradingfrequency.com_ehn4guw6
- 99107c81f8e71985b0fba0f5b4a1fba336acd3d2c0b8c21ef4c4f9405e25ec50 http___h-miyoshi.ed.jp_eggteyujbx
- cf556fd0c94d97b07592f7403f099250a0f756b78b04bf16b66d1eb94b074d4b http___interprofil.no_imjsj7gh0
- b73c01a07ee58c6ac3898dd6d2a690739a124a4b084896b54ede3cc98e46d720 http___islamhizmeti.com_4rn5re
- b102181376e7aeaeb093b0ec29adf0fc71176459be3ce42143836fd42f0a8590 http___ivocal.fr_tydqws08pe
- d17be6532a28e663b4d636b13472e44d7157193fb62929b41b0fe583b0909379 http___iwebsdns.com_k0ais
- 774d788a86ee1d4642ce5f9510936f5b8c9d8ba6d5f6fbfc728136b9e6cd443b http___janzwolinski.freehost.pl_v8xnbq
- 99819236cd025c0854581c276c484160b6306e1a5007ea8adcfb36704e9062ad http___joelbodhi.com_pr1qz
- 66de39c0fb972fca2dbd53e9e6923c29e796bb75a0af385884f7308958f70689 http___joelbodhi.com_qalnt4t
- 7b8460c7f5f50e2064499febf255d9c54c6d3539461207f780eb100ffc9306fe http___joelbodhi.com_r94yyaty
- 1876aa754208c0cfea4a5845636194dc0189ea418e1f3cd2e116de793637d567 http___joelbodhi.com_srcdv0jg
- 2d5320f24da8f944b5b01de850712e2ce301d327fd9fbcb83f0a18310997dd52 http___kleansys.com_y7oragomg
- 38fbb143a05a926bf67ef5300f17878516247b181f986833e0aad45ca5520b46 http___kolumbia.free.bg_trbwdtze
- 7b7b59277a906e1f119d8e7626a270acf075c7580d765d9a7b3b79d1149f128e http___lecitron.org_rozculcvba
- 0505b7b38f84e4cdb96a11e7ab510599563da4287ec378e88d90d2adfda5992c http___leliunion.net_e9nw7
- 32d79e6bf7d478c6284dc0dcf3f1fcb4283901f2f5c41dcf35b359e1f45d28e8 http___leliunion.net_jhczf
- ba9d36f9877879f15ed1df97c0e6b408571fa46539d2729253b1272bfbffc357 http___leliunion.net_kwnlmbgrv6
- 1f4d611970785780090d5e0ea7408e7d7d2c3674a9d9a0c2ae280a889d92a313 http___leliunion.net_vt2dyzq
- 93d46be040939f47878e678b5f59da039d1114612d2f57120e28d295cced9819 http___markscheffel.de_wqkgiuama
- 59200c26621fb891fd97b643cf31c40c33c665b757878ff14d4d733ed8c379dd http___masterimob.ro_wbxglxsh
- 115f600b26b5340fccfecf2ab5b296b80bed72b455680c310288bae294f26f8b http___materlux.ru_qwn5gh
- 42429075dfe4f4bdc7b8054d9c8661f6936a91ec3c49413f4d76c78aff58b43d http___mdk-wear.ru_zwd98vmv
- ecd462f1ca246f068786fc77407b87674c3c9fd8c4310064f06b81d6c5c86da6 http___mokinukai.lt_x4szqe
- 78e87e0ae865e4c22f56d6f23a53f109a8054df02758df8bca10acb9096909c8 http___monster-high.com.ua_tah7tzqdfq
- 8b7402f0b1f38a7cc51294a6f5c8ec109fea748b06c1ab7abc4afc347a972a45 http___mufengzhai.com_yfnglx2
- bf276b6b98b3c1f9f30198f6dc9f6ba23e7638e1766fc940b5625966ec105bde http___muricreklamcilik.com_6qycx
- 03816af40575d265b74a3a5970fbd41737adbde146c988eb778de6886dbb95a5 http___musicrecruiting.com_xjlecd5ju
- 7356b4e4cf18288a3b4a7b67ffdd0f665b102c2b4d9c76f25616a54ddd7b6c6d http___mytourbid.com_5c32pzh
- 50df3ba1f6a7b5f5945a86c065efb39226d242549445f8aedca8279395014395 http___naruby.kvalitne.cz_t7h9qce6h
- 22d5ef4057b2322681b0fa7cdba0036be17947eaecddad792d812b7685dfcaa7 http___nicputeec.com_6rm6xf
- 231d8c93a945cc33f2ccc3ef0b791f1f72c93f9ad78c57554db10933a1f02de8 http___noisecontrols.com_4nqceemivy [3]
- 7dfa745be88dd7ed35e3b3890e8b1093dc5586c2ee479db31f2c29e9e56e1db9 http___obsidian.cl_3zttsnxknq
- 63d384f015d6db7ca24afbd0ae992dd8d28ea1dd3034463e51090ef64c9dbf0b http___oimeferio.net_glotrsefkp
- 698da725752063b7ff076cfa84f26c8a833e857e0c9fedf42282936ab3bf2088 http___oimeferio.net_sl60vc
- 181e6406901afc79ea129299fbf432e2babde61241bb7acf8d6fb4c477c139f0 http___oimeferio.net_u25orc [1]
- 7d1eb456f54ca5dd020f7b72ecffe7d06f1f87fec91fdae555f3098b73a410bb http___oimeferio.net_yjibxujt
- 914770058a53342fe68b7964e59aee24ce74592ac631f9c5b2c0d809802f3427 http___ooomaksim.ru_591bwwbcu
- 8fdc893a6b5ed48f97276d37bdf7d257148c867dcaa66f4f36a211ae499a9224 http___orantpamir.net_el3w488r9
- 32508e66382ad7965d25e915cd6618705e41089b32b17513441eadc064b2e081 http___orantpamir.net_lyzj9ja1uh
- 3799ee952595746696dbce8c0a485a375e1a591a848e639c3b57cdc85ca800c1 http___orantpamir.net_om1twg
- 96ad734a215f075e710ca4987e15eb88e00375cc8467a9d77b44afd74611b476 http___orantpamir.net_rtss2coyh
- 516e60d41089e6171c89647f021ee43ddaa25e58929e051e5a102aecd1177ac4 http___orthoskin.com_1e4mdliv
- 71fe46858593083ad60a242d40a06dea5e47362ce542a9694a52d6baa8ae695a http___paddamar.net_0k0n5zjze
- 00c7496a6b4ba948214735d6b04cc5f7f9dbf8225eb6cf2a57e884530d946eff http___paddamar.net_gqmfsfvg
- 8219fbbebdc62340ff922bb4e2b64f67a26ffeb624d49831b4f24ebdbcfcd1c2 http___paddamar.net_irz4h
- d333ede38b87b72fbefdbace6147d82d3949785fb485858848af62888e2fff4c http___paddamar.net_w3l68g [5]
- 2e59b9a764f5a786d94a40a1544a5176a015e1e328a3d5af87c9cc4f275259d0 http___panificadoraavenida.com_5ren2ksdu1
- 9927b60787ce1b660deb6a3f796d30d14773752009ee2d1298a280af3f218ca7 http___peruincoming.com_2asklonmy
- 82520faed846998c544fac9bfdf25165890d15f3e76febfbfb7d7f83cf870385 http___rentalpark.com.ar_1useo
- 651eda5f59a51c891634a53e16814425722fd15fa136debff721a84867d15e49 http___vikingradom.freehost.pl_jizvw5rg0u
- - decoded
- 1e38e8a161c2da46561eba97c86074546a7bc6d8fe820416e197a214815e4e6c [1]
- 5e448e607111b4c1cd1bc34ccccfee32827bd06eacd04ccfb5f754245bbc0027 [2]
- 4f7198f7a180ec0087d88f58b62af438ef4f3449edb6e925ce399664e61c9d76 [3]
- 59b705084f23b382b8ff146bc5cc0ef42435bc9fb358c832974d5c6a534e74c4 [4]
- 6a915350461d4b9452fe4261af91ff965e62d056471fea81644d49a8c6bd601f [5]
- - executed by "rundll32.exe %TEMP%\<dll_name>,y600cBdKt5HYiTFVZ2d2zeKKA1n"
- C2:
- POST http://46.8.29.176/information.cgi
- POST http://95.46.8.175/information.cgi
- POST http://ayamspq.click/information.cgi
- POST http://buhymxevtxw.su/information.cgi
- POST http://cfenwdknibebspcv.pw/information.cgi
- POST http://dtfnfxhapjy.su/information.cgi
- POST http://gflmbdprdxfqkwffc.su/information.cgi
- POST http://hbvgmensk.org/information.cgi
- POST http://jtfirirnurnnopyd.ru/information.cgi
- POST http://kmyllud.ru/information.cgi
- POST http://ksyfkbebtdh.su/information.cgi
- POST http://nglfueplskojeq.work/information.cgi
- POST http://nqwsatjtjepmecc.xyz/information.cgi
- POST http://ogqwjmgcejfsgfxbh.su/information.cgi
- POST http://osohihqtjyvxte.ru/information.cgi
- POST http://rhifaouxqbcvva.pl/information.cgi
- POST http://swtfgrmkudtlcawkt.su/information.cgi
- POST http://tufvchfnyfasfhyh.pl/information.cgi
- POST http://wuismdvolqbhlrcm.click/information.cgi
- POST http://xgjjaedtahckomf.click/information.cgi
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement