Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-12-06 #locky email phishing campaign "receipt"
- Sample email:
- -------------------------------------------------------------------------------------------------------
- From: "Alexandra Brady" <Brady.Alexandra@muza4helen.ru>
- To: [REDACTED]
- Subject: receipt
- Date: Tue, 06 Dec 2016 23:59:33 +0530
- Dear [REDACTED],
- It is Alexandra from the delivery service. Recently, you've made the order in our store.
- Sending you the receipt and full report in the attached file.
- Please inform me if you notice a mistake.
- ---
- Best Regards,
- Alexandra Brady
- Delivery Service
- Attachment: receipt8218966.zip -> ~1OKDB661ZR32716YU6UA8V.js
- -------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "receipt"
- - attached file "receipt<7 digits>.zip" contain file "~<20+ uppercase chars and digits>.js" a JScript downloader
- Download sites:
- http://4djsbydjs.com/ffi5tpbui
- http://artsonimage.com/b7d2pn
- http://be-liveinu.com/gcc4vi0jyb
- http://benefeet.org/a4ztilxpex
- http://bjarnum.eu/pjj42gl
- http://brei.com.br/kyi5l
- http://cementossj.cl/qrgmkmi
- http://childrenshouse.co.za/1v0lblf
- http://chocogaterie.eu/lijxve8
- http://col-lab.com/m1p73uqdeb
- http://cr-inos.com/lzwiz3d
- http://diariolatitud35.com.ar/edkij4anq
- http://elizabethwright.co.uk/ode8hifc
- http://fonteaulente.com/q5vpvcz
- http://galeriamultiarte.com.br/osn2bj
- http://gaozhao-edu.com/jdspeeimvz
- http://gocatering.se/ctrshwvx
- http://hotelmira.ru/on2gh
- http://hotpeppertrading.com/iuuhioli
- http://jachin.co.kr/n48wu8a
- http://koresh.co.il/9uoctzb2vo
- http://mirageaudiovisual.com/jflp9dkxsg
- http://naama-yeshayahu.com/twibpn8don
- http://nechtyela.sk/k7ras
- http://nekkel.pl/0apru
- http://nsecoaching.ca/cd62kg4btm
- http://nyxiaoyuan.com/uig0dyc7m
- http://one1club.com/8iqrtn
- http://pregnancysquare.com/wk97j
- http://quentinconstruction.com/jcmprfrr
- http://rabussa.wz.cz/x08gte
- http://radom.nl/zdknyeq0du
- http://rampas.ch/xc2clj
- http://realearthproperties.in/surhnrm6xv
- http://redecamponesa.com.br/bovofik
- http://renklerle.com/vycrub
- http://restauranteelveintiseis.com/antpme
- http://rhyzrin.com/ysacclh
- http://roome.co.il/uc3bhhxwoa
- http://rosispitaniya.com/x07nn
- http://sieuthicuadep.com/jwqwt
- http://specimengear.dk/2armwx
- http://thedivafiles.com/29gce0ube
- http://trehoada.org/rakk97
- http://uriauerbach.com/l87aw
- http://welte.pl/czdpf6
- http://www.beautybydesignonline.com/prsvu
- http://www.clap4ya.com/1eodzfvkg
- http://www.cvshopfactory.com/da9p4ja
- http://www.dahuahdcvi.com/4yjo2ewbam
- http://www.globalem.asia/gsup38l5
- http://www.gostaythere.com/7oemd
- http://www.izmirtente.info/itccwdk
- http://www.secretblog.de/j3m3iyomrh
- http://www.seecomedia.com/qem1cmp
- http://www.smartkutu.com/eijjjici62
- http://www.tacfitacademy.com/i46phb
- http://www.tvblanket.com/baxullbrx
- http://www.veinteproducciones.com.ar/mcren
- http://xn--80adixsmm7f.net/9c8cqg55x
- Malware:
- - encoded on download
- 33c17b64e30e0a2438a1ae26fb1ea1665e33dfd5758a064f98302bc6bee7b16f http___4djsbydjs.com_ffi5tpbui
- 403541bfbb4a2ac1f37c10bc0eb7d322b6ee1565d6ccc64c2dafdddb9dd10577 http___artsonimage.com_b7d2pn
- 47a7d09614f522e9fb7d8923edeced5c44ad68ce1ffdad55d5956229b44ab2b5 http___be-liveinu.com_gcc4vi0jyb
- 577a7897bac5607038de138075d47bf9b2727686a872446625ab6728441eaac1 http___benefeet.org_a4ztilxpex
- 055fc1a739311c35b97426b46b0c45d6ba1425c93bbf229aca748eb400440bc2 http___bjarnum.eu_pjj42gl
- 6c24d9453395921047c50356d8b0fdd484a8fdf4ada7b7560731882d7eebd57e http___brei.com.br_kyi5l
- 6983909d12324a890091515e043fa451ab9ccee6c11606e9771f225db78160f2 http___cementossj.cl_qrgmkmi
- 1815ce50dc83b50489f9fe1ebbb00f38015d87f55b809120528486894fbc39d4 http___childrenshouse.co.za_1v0lblf
- 3cf890c743965b2453f5cab539313841ce54e969ab2dac551536f52c3dc98880 http___chocogaterie.eu_lijxve8
- 2fbfc5e049d4f707fdc6d7b9ceb6359d6786871300a662016469e61036ccfd92 http___col-lab.com_m1p73uqdeb
- f3d27d7285e1a0b03edaa6bebea98418357eae02e55a9f8b0f9ceeaca81908a0 http___cr-inos.com_lzwiz3d
- f9757873a9d78ec0e0fb6b34bee4e66da236e5753f676dfac4fabff98bfa1357 http___diariolatitud35.com.ar_edkij4anq
- b25d559acd45c81374ed68110df0530afc907c283219ec4acad753441173df71 http___elizabethwright.co.uk_ode8hifc
- d591a17a5b33b033d8248993b66f3d1088eb4a50642b0d8330b6fa052e2a47b8 http___galeriamultiarte.com.br_osn2bj
- c2b9130a2bf40a064a4a5e0dd89be945653228616935bba2367b880fa04dce05 http___gocatering.se_ctrshwvx
- b8f1fcb615a652c81930ff004ff1f0b3ff089c43739ba62929093b8253811b23 http___hotelmira.ru_on2gh
- 4720b06d0371ad8cd9e8b4490a33ac759f0d2f11482e157eedbba9a891b42e4c http___hotpeppertrading.com_iuuhioli [3]
- f91c5e5132c78c7f9404d967504ce1f2f8a4baa131ed825d42f1d3e7165676ad http___jachin.co.kr_n48wu8a
- 49c33c5d094d4b16b65e7c77a837469e9f1132327e3973b13253781d7ed3828d http___koresh.co.il_9uoctzb2vo
- 26af455d8479f0b06eb39dcaba8f2531f9dcfbca36976eb393d599c26b772fe7 http___mirageaudiovisual.com_jflp9dkxsg
- a76edd607dc3d9e56728831d6f8e4e9e49568c9a78267f6299496b3c293df37d http___naama-yeshayahu.com_twibpn8don
- 36291fe4f899c6e2680f02f835a1b46c529619d870a89dc85cc244e93c27c58e http___nechtyela.sk_k7ras
- 63d78d6b8495494bec0b11431aa1404fd0bef51d70da585cec67204b74412e72 http___nekkel.pl_0apru
- 787b1c3ef91a7122c7d941b863c7890e52b86390e110fa4a73a58d0c4e7c208e http___nsecoaching.ca_cd62kg4btm
- 937a28ae89e950fdbcf3ecd97c7db6bb8138ead04b0ba9b0fdf3af6942601502 http___nyxiaoyuan.com_uig0dyc7m
- 5a01238b1ccbe6da39cbdea14a50e3f4ccd96bc786ededd52f681c4bf37f54ee http___one1club.com_8iqrtn
- 613783b4d6d2ae0fcdda1e1bd6c83ae1c0483049a7a3e1a609840a01372f4bdc http___pregnancysquare.com_wk97j
- 50e25b3bec47f265fbbe938b9385f168d57e2f12c1a0a94475a70bcfc1ecea7b http___quentinconstruction.com_jcmprfrr
- c53ef809dd4ea7b392300381ebba2de1604b502bf881b5d13108b86dc863aa51 http___rabussa.wz.cz_x08gte [4]
- a6cc5def802326d2ed167e3878b7ad22c6efada11c2760590dd1cfc0fc822696 http___radom.nl_zdknyeq0du
- c0017136bfd4d167e1941b0ce8d1f79e425503a1be02f586a4be8cd641e0d54c http___rampas.ch_xc2clj
- 18e4405aa556615b698e011fcb62a0103afee0168cac3989b516053b4e5dcb6d http___realearthproperties.in_surhnrm6xv
- b245db730bfb465bbcf774d93025d9f734cf2494724a545f3b7d3d2cb8632acd http___redecamponesa.com.br_bovofik
- f57e7b185faf3f0d9076eba900940adeaede73249333944b65592051e88da916 http___renklerle.com_vycrub [1]
- 281c0aedd1931ac8bee0d3f06da45b2a2353e15ea41364ab6411f79e1c766291 http___restauranteelveintiseis.com_antpme
- e99994d395fb50c3003a9cd98dc28a91a0a9cee78047916f3a55101f2a693726 http___rhyzrin.com_ysacclh
- e5f26ea9001b03a22bfb419eae764c292d8035bc9336763386047c2ce5bf7606 http___rosispitaniya.com_x07nn
- 920c5083fb7944d91f17af58ca79f3bee82169b77f3a21b2f02ef829f74c192a http___sieuthicuadep.com_jwqwt
- 72c22c2f518eae6f6a73cfdfc2f1dfe46a3f0bc203623f1160036ea4aef521c9 http___thedivafiles.com_29gce0ube
- 9c9b06226428624ff69cf557798d06d03b677971295eec496752712707ebf089 http___trehoada.org_rakk97 [2]
- 4e134c0f19d8fcc05d15b4d2721d930c184933af0d79fa24c93d86ac1638d8e2 http___uriauerbach.com_l87aw
- c41a261d52b4c8bd66d76878685a8fcf48d3a5abd0b7b2fbd956927992186438 http___welte.pl_czdpf6
- 5ea0eb7264d604040b7ab94ee72b28eae5bdc7714c4f59a59a991ad4fc822929 http___www.clap4ya.com_1eodzfvkg
- a285d71fccc015d070b0281678e12830f5ad461992c8aea9ae8aa21a70573340 http___www.cvshopfactory.com_da9p4ja
- 40b06fa9dfdc64fe521cda72eff5e254fb14b6f536eb4aebb0c8d31a06c5fd80 http___www.dahuahdcvi.com_4yjo2ewbam
- 07d77e8a898919c2086530ecc8b1f3901bb37b04a614ef183c0c73302601ee1a http___www.globalem.asia_gsup38l5
- 256bc85eefecd50de4932fc9d7481f32e46a585dc0d5a4c2b861966620f0fd52 http___www.gostaythere.com_7oemd
- 99397be74c9c24d19442d0e69d09a1427c2f2d0ffb055427605f667fad3ac6e6 http___www.izmirtente.info_itccwdk
- 561e12f86be53ce1624bfab1917d8fa5de6b31a35810497e1eb09549faa7b900 http___www.secretblog.de_j3m3iyomrh
- 0d3c970fe679042d3cdf5706964e0492ced900d8c446cb75644befcd1e03f2b0 http___www.seecomedia.com_qem1cmp
- c14c54b6eafef7cd7920756b28058017482c7982dd4ed381af0133fa86938846 http___www.smartkutu.com_eijjjici62
- 3f9f69973d8f46682ae985f2aa470828f03c38999f1dbb1a7132d5811fc8aa70 http___www.tacfitacademy.com_i46phb
- 17d903fd51a982c556b9074c67579f85d43f3ce07ab0cc3cbfa6f201ca17e519 http___www.tvblanket.com_baxullbrx
- 70b4965933aef25335687f674bd5cea911e58d7cb62bb94361cb123c27badd82 http___www.veinteproducciones.com.ar_mcren [5]
- - decoded
- 9bb9443c8ba53c8258c5da3f15eac0b99e7f7eafa48d39b7418b04e3902fbcc0 [1]
- f5aeefb3f564d9f47ae1fce39f72a7bc7108d293e4367a7cf38658c28937f34b [2]
- fc2df5f9b2d33bb2156adbf1d881e369575adbfc993750732571cbd65c7d5396 [3]
- 0b2bc6c2391d80228318dee837266204d638c62eb982cde7ed6af92519ecabc9 [4]
- 67aedf0ef9af87d3f543b0d4eb4e1da9367ac6760c10239e793830d13df86bdc [5]
- - executed by "rundll32.exe %TEMP%\<filename>.ZK,JAMPK8tM4Gv"
- - samples
- https://www.virustotal.com/file/9bb9443c8ba53c8258c5da3f15eac0b99e7f7eafa48d39b7418b04e3902fbcc0/analysis/1481100689/ [1]
- https://www.virustotal.com/file/f5aeefb3f564d9f47ae1fce39f72a7bc7108d293e4367a7cf38658c28937f34b/analysis/1481100697/ [2]
- https://www.virustotal.com/file/fc2df5f9b2d33bb2156adbf1d881e369575adbfc993750732571cbd65c7d5396/analysis/1481100703/ [3]
- https://www.virustotal.com/file/0b2bc6c2391d80228318dee837266204d638c62eb982cde7ed6af92519ecabc9/analysis/1481100710/ [4]
- https://www.virustotal.com/file/67aedf0ef9af87d3f543b0d4eb4e1da9367ac6760c10239e793830d13df86bdc/analysis/1481100715/ [5]
- C2:
- POST http://176.112.219.101/checkupdate
- POST http://194.67.215.228/checkupdate
- POST http://85.143.213.71/checkupdate
- POST http://91.203.5.176/checkupdate
Add Comment
Please, Sign In to add comment