Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-03: #locky email phishing camapaing "!! Urgent payment request"
- Email sample:
- ----------------------------------------------------------------------------------------------------------
- From: terri.stanley@faroldovale.com
- To: [REDACTED]
- Subject: !! Urgent payment request
- Date: Thu, 03 Nov 2016 18:06:03 +0800
- TERRI STANLEY
- Telefon: +49 5055 / 51-8502
- Fax: +49 5055 / 5166-8502
- E-Mail: terri.stanley@faroldovale.com
- Attachment: "2620800243-8943568474-201611180603-0680.zip"
- ----------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Urgent payment request" prefixed with 1-3 "!" and space
- - attached file "<10 digits>-<10 digits>-201611<6 digits>-<4 digits>.zip" contain file "<10 digits>-<10 digits>-201611<6 digits>-<4 digits>.js", A JScript downloader
- Download sites (actual URLs contain suffix ?<random>=<random> which does not influence download):
- http://020zz.com/jhb6576
- http://0551gx.cn/jhb6576
- http://1kupon.com/jhb6576
- http://3-50-90.ru/jhb6576
- http://abclala.com/jhb6576
- http://adj3.pt/jhb6576
- http://aertsbonarius.nl/jhb6576
- http://africantickets.de/jhb6576
- http://aizheni.cn/jhb6576
- http://ajmontanaro.com/jhb6576
- http://ajooma.nl/jhb6576
- http://akram37.com/jhb6576
- http://albakrawe-uae.com/jhb6576
- http://alpermetalsanayi.com/jhb6576
- http://aquatica.at/jhb6576
- http://arbeiten.pl/jhb6576
- http://archmod.com/jhb6576
- http://asaproducoes.com/jhb6576
- http://autoparts-outlet.nl/jhb6576
- http://avenueresto.com/jhb6576
- http://badaprogres.es/jhb6576
- http://baseballtivy.com/jhb6576
- http://bbq-tech.com/jhb6576
- http://belaket.nl/jhb6576
- http://belusadba.ru/jhb6576
- http://berrysbarber.com/jhb6576
- http://bestoptic.eu/jhb6576
- http://bg-n.nl/jhb6576
- http://bipmwebs.com/jhb6576
- http://bradandmel.com/jhb6576
- http://britneyspears.website.pl/jhb6576
- http://caballerobustamante.com.pe/jhb6576
- http://cafedelrey.es/jhb6576
- http://carbonfiber.ro/jhb6576
- http://caribbeancopiers.com/jhb6576
- http://centinel.ca/jhb6576
- http://chinasymbolic.com/jhb6576
- http://christophflueck.ch/jhb6576
- http://cisie.pl/jhb6576
- http://ck.co.th/jhb6576
- http://clickjv.com/jhb6576
- http://clubchasseetpechedesamis.com/jhb6576
- http://comercialtrujillo.es/jhb6576
- http://competc.ca/jhb6576
- http://continents.com.hk/jhb6576
- http://cor-huizer.nl/jhb6576
- http://cosywall.pl/jhb6576
- http://crecrec.com/jhb6576
- http://cwv.cc/jhb6576
- http://dentastyle.ro/jhb6576
- http://dessde.com/jhb6576
- http://dietafine.cz/jhb6576
- http://dilovasicicek.com/jhb6576
- http://distributorsite.com/jhb6576
- http://dornovametoda.sk/jhb6576
- http://dosq.es/jhb6576
- http://drkitchen.ca/jhb6576
- http://dutchcotton.nl/jhb6576
- http://dwunion.com/jhb6576
- http://dx-team.org/jhb6576
- http://edcentre.nl/jhb6576
- http://edumarvm.com.ar/jhb6576
- http://electron-trade.ru/jhb6576
- http://elektronstore.it/jhb6576
- http://essenceofbeauty.ca/jhb6576
- http://evirtualteam.com/jhb6576
- http://e-ws.net/jhb6576
- http://faiz-e-mushtaq.com/jhb6576
- http://familieheigl.de/jhb6576
- http://farko.eu/jhb6576
- http://schuhdowdy.net/jhb6576
- http://teriisawa.com/jhb6576
- UPDATED:
- http://avnbook.com/jhb6576
- http://ccilfov.ro/jhb6576
- Malware
- - encoded on download SHA256 2d3bdad21984a3fb3a38d7b0ae6194d698333e6254a423ea724921ef7367ccb6, MD5 0dde5161009954ee77c9f12e693bc91c
- - decoded SHA256 0e6bd3de7ac49ff4438a592892e0bb8da9596be4ed8328459c239c6f3b4dec86, MD5 21a782f9b1089fe169279d5a56aa6719
- - executed by "rundll32.exe <dll_name>,text"
- C2:
- POST http://109.234.34.227/message.php
- POST http://194.28.87.26/message.php
- POST http://93.170.123.119/message.php
- POST http://avqraxyq.pl/message.php
- POST http://disvfthejnadoufh.biz/message.php
- POST http://dspdepmduhduk.work/message.php
- POST http://fnsacxejerahf.info/message.php
- POST http://heihlcvfcexxxqvr.click/message.php
- POST http://lbflexv.click/message.php
- POST http://mbmeeayr.su/message.php
- POST http://qvepebtlksgxel.su/message.php
- POST http://thfafqhxyiwf.pl/message.php
- POST http://umfhhrwfws.ru/message.php
- POST http://xecemaekvltyv.xyz/message.php
- POST http://ydcdxki.work/message.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement