Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- *Email sample*
- _Subject_: Fw:
- _Body_:
- hi [NAME],
- Here's that excel file (latest invoices) that you wanted.
- Best regards,
- Darnell Hansen
- Group CEO
- In attachment a zip archive with a javascript file.
- Javascript sample - MD5: 2cc72f8c2c1722cabcc8612c4d647c21
- VT: 3/54 - https://www.virustotal.com/en/file/c9662190357968e8aa163a87ed1009700393f6d6104b9eeae0051589d60e49a5/analysis
- *Compromised domains (46)*:
- acepipesdeli.com.br/ tffx7
- aerosfera.ru/ h5vkp87
- agbiz.co.za/ x2evw01
- choogo.net/ qi7j7f
- control3.com.br/ 57nhtzkv
- dealsbro.com/ 4qtc20
- diablitos.no/ ogmrgs
- doisirmaosturismo-rj.com.br/ jxdlzcf
- eskuvotervezo.hu/ 3kbgy9a
- eusekkei.co.jp/ tdts0
- ferozsons-labs.com/ 52sf0l
- games4games.com.br/ ubabtp
- globaldveri.ru/ i4a3l0
- hanaweb.xsrv.jp/ be6o4g6
- heonybaby.synology.me/ 41sx3e
- ialri.net/ tughk
- jsbaden.jemk.ch/ xyn8moxt
- jstudio.com.my/ 5mkejwj4
- kveldeil.no/ opca2v2
- maihama.2jikai-p.net/ 5mkejwj4
- mcpf.co.za/ ffq1mq
- mphooseitutu.com/ tfq5e5d2
- mywebhost.nichost.ru/ g53y7
- nicesound.biz/ 42did
- omnitask.ba/ ac5f6
- ostrovokkrasoty.ru/ x7lcd
- ppf.com.pk/ 5z2sk
- quaint.com.br/ divme5d
- repair-service.london/ uywgi7v
- revengeofsultans.com/ 9cu7bsw
- richard-scissors.com/ wife8eaf
- rigoberto.com.br/ nqum54t
- samaju.se/ fsqrtgrm
- sindsul.com/ h02sujs
- sirimba.com.br/ qiovtl
- stylespiritdubai.com/ be1id
- tvernedra.ru/ lob9x
- valsystem.cl/ v4db1wd
- wacker-etm.ru/ jfbmxlhy
- wineroutes.ru/ hrzl8dw5
- www.cristaleriadominguez.com/ fxcx6ep
- www.inextenso.hu/ xc3739l
- www.ital.com.mx/ xswj9
- zachphoto.7u.cz/ 0jyhh
- zakagimebel.ru/ krcsvf
- zoomwalls.com/ zghpzv2f
- MD5 Hashes:
- 01d7d0666d8894b4b7757e7755e404d2
- 03bd2441639bfca4d4cab82182b13259
- 1ba8443c770d197c4637af57645baa5b
- 1cc933aaf7f974f248077929ab08966e
- 1f969bc14b47f74e3d89490406602329
- 218ccfd206bfc627fb62999ee18c831b
- 23ae38bff24b441101931aeac266f91d
- 2911ff9cf53d0f63abe8449bff199e4b
- 2c641d77cc7ad576c351f8e33125b602
- 2cc72f8c2c1722cabcc8612c4d647c21
- 311d35de7967969bca0b9e449db37d04
- 37692dc630ec80459f8f97c1cdb94df5
- 41a5c668efb0bb4968db5f1d3ae8aaf7
- 4c7675bca5e9098223a94f99dc2669ba
- 5076fdf1c68b770a5134e05d120e02d4
- 593abc2caa50d7eae2564a5b644178ed
- 5c84852b839715359ba35cff6d92a919
- 6391237947b65877aff8dab5b4d0fc81
- 67b0dc635a407997a35ac7b3b44e07cb
- 69e1504fe58aea24b8176d12468d0083
- 6d8566ae39760bc7928efb174525f75f
- 72318e26401a03b103b7eac41dc6b317
- 74c701fe0bb0e096acf74e7bdd8bf1e1
- 78fce7895b9df71f95fb8319f7701f6f
- 84e5243838213d1826d8d3333f0db4c3
- 89aa5cda2d264866afd6912dd299bfd6
- 8ab7b9b043df6a8c4680845f74cc75b9
- 8d4ecd90c31546522cfc3c9c2ccc0b3b
- 8ffc22504accfb8a9e890e5d563e8e88
- 9294034a48654fa4f31b74d009c90b3f
- 95870e27147b5767f29370609dcf552f
- 981bf21648e5b6f53de170b4265b67c3
- ab45937a7acaf9a541928258c03a51ed
- b0c01c692d6867e3167a0b3075f8cd1f
- c02607f2417620bed327e8974451ffbc
- cd853bc211138cffb815b7420513f816
- cde8b2582a940aafb72f20e21e572f03
- d6622ecd2cbb9dc635dbfc28c9b8f9bf
- d8a680a32a6a8a6251d526b02d0ed49f
- d95f77ccf08dbf1c74e6dc11eaeffa9c
- e2408e8f0539a3cf3842dc978e505778
- e5862593c3b2cafc60a622b07cf1283f
- e64d9f1df9ac4cb2a9714edbdedb5df2
- f55c2928edf51378a9a3d340f1172e70
- *Sampled downloaded and decoded*:
- File Name: tbb7itlAhl0.exe
- MD5: 98279DCF61AA13DFC55F3298C3DFDA02
- VT 2/54 - https://www.virustotal.com/en/file/39a3b9fb661b5316c46d0125621c2b622cd99f8f5c500d32a63a37a70a9ef8ac/analysis/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement