Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-21 #locky email phishing campaign "Receipt"
- Email sample:
- ------------------------------------------------------------------------------------------------
- From: "Kristopher Livingston" <Livingston.Kristopher@elementeight.com>
- To: [REDACTED]
- Subject: Receipt
- Date: Mon, 21 Nov 2016 17:27:18 -0200
- Hey there. I transferred money to your account. Please check it out at =
- the earliest possible moment.
- For that, open the receipt I've attached.
- Later.
- Attachment: transfer_[REDACTED].zip
- ------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Receipt"
- - attached file "transfer_<recepient name>.zip" contains file "<random upcase chars>-<random upcase chars>.js", a JScript downloader
- Download sites:
- http://ablerkeawe.net/4sbcti9e
- http://ablerkeawe.net/7bikbjivr
- http://ablerkeawe.net/bmh9z8ek
- http://ablerkeawe.net/n7coe
- http://alamanconsulting.at/dhwe6and1
- http://ayso722.org/yenon861
- http://cuordicioccolata.com/zwxzq3d
- http://dangdika.com/1besn
- http://dangdika.com/mn3x8nkv0g
- http://dangdika.com/xclh8ia
- http://dangdika.com/xxdswup
- http://doughdata.com/vbubkput29
- http://edu02.ru/uzwjx
- http://emdrozd.net/uwrecjic
- http://espansioneimmobiliare.com/zq6xw3mi3y
- http://fazendacristal.com/xcpidywxz
- http://gerardfetter.com/vl8s7d0e
- http://grandfm.com/zlhmy4dq
- http://guymorgandaily.com/xjwgh
- http://hfhhk.com/xaox8be
- http://hosimin.com/l10nzv
- http://hubis.ir/cd2tvfn
- http://icnvcopa.com/byddwdjk
- http://identita.dk/h0vxv8zxh
- http://iliebike.ro/ogqztl8
- http://iluzja.pl/0byxmqj
- http://indirimtakibi.com/17k5n
- http://inspireyouths.org/tg3kzh
- http://intensivo.nl/c1klzfc
- http://internationalservice.ro/leg893
- http://introfm.com/f1s0y
- http://ipiasarnano.it/cthwsd
- http://iptravel.net/5h63oeoy
- http://irnetshop.com/dfvltrouq
- http://i-school-tutor.com/3phcz44v
- http://jpbroker.es/oxqtzrqhm
- http://kexinbuy.com/q8rvf1dzxr
- http://kidpublish.com/ftk5zaqp
- http://k-koubunsha.jp/5vb4zq
- http://klautorent.com/hunv2qqm9t
- http://konya.ocart.co/kvcwgeajv
- http://krucekpokrucku.info/bhke02u
- http://kzprojekt.pl/hb3az2xwye
- http://lanehmontgomery.com/obqa0iwzj
- http://langzhong8.com/bbxicl5h
- http://laszloiparcikk.hu/fmgqm
- http://lihunyihou.com/qjc9vxc69
- http://lomtour.com/iziet4l3
- http://lvyeqingtian.com/auntes
- http://manhtienphat.com/5ko2h
- http://marinaensenada.cl/izb2fj1gox
- http://mice.co.th/n96w5nl8y7
- http://mildreddeskinsjewelry.com/itlgzij
- http://mileswebhosting.nl/0b0cyt
- http://minigal.cz/k0v3sxvys
- http://moswomen.ru/ilteiri
- http://multicombs.com.au/fvmbusvz
- http://mygfiltre.com/k8w97ku
- http://naturalcode-thailand.com/5py26ttl
- http://nnptrading.com/tbfr7
- http://noahapparel.com/pxggxtk
- http://phaleshop.com/wpcnm4
- http://tafiathiol.net/19p1knzx
- http://tafiathiol.net/jxirmy
- http://tafiathiol.net/kebxo
- http://tafiathiol.net/z3jo7fwzu
- http://tapersk.sk/vhu3cs5lf
- http://tupsorva.net/9eytfon9
- http://tupsorva.net/db5z4a
- http://tupsorva.net/mzjlk
- http://tupsorva.net/py6gfd
- http://vyingouch.com/9m0qcj
- http://vyingouch.com/c0jnk6
- http://vyingouch.com/hqeaas
- http://vyingouch.com/nseam1uiq
- http://www.dominoassociates.com/ysojeahx7t
- Malware:
- - encoded on download
- ec2152dbd6a49a1468be5a888d0fdfb407af0730e60b58dfd375313f9d29bfb0 http___ablerkeawe.net_4sbcti9e
- d323b5bb27c15e5b98d186219de19c0c1194e6b8e4560180f3acd5c9051ee600 http___ablerkeawe.net_7bikbjivr
- bfa8907cf4c991df64a1d69420456292ad4c98562ea4814c8da5030951b83b85 http___ablerkeawe.net_bmh9z8ek
- 1228fc8465ff2d15434eadea98673fcf615c762a2a1d7b7df12bc66313dd7f26 http___ablerkeawe.net_n7coe
- 67c4ccb963d9f002903c4192a6bc1e30b4a6a87690c19075b81cc9a757483148 http___alamanconsulting.at_dhwe6and1
- 2ce82d2cf066efdf70d01234589bb7d2ba1cd136b30eba14fee5c23bdeee4a49 http___ayso722.org_yenon861
- cfaa5a7561c36f440e79a2e3c7fb5b4439caa4b8ff0a86fa44ac89f46183a960 http___cuordicioccolata.com_zwxzq3d
- 70e4dc73b1cdcfb9cadd004f8da9d25534e8516e9e9e9fd019d149f85ede0575 http___dangdika.com_1besn
- c191a6c87975bebcae8681f5146e8103969e5660644f9bd28d429df83720b5f6 http___dangdika.com_mn3x8nkv0g
- 8f125e292f06c846c435aa25632ff424a33aa9f489b1458f139c6927cb48d606 http___dangdika.com_xclh8ia
- b3ec70a1c6262547ecdc7ee0f4aab1ff048691991059a01560c64ba8d9f6ebbf http___dangdika.com_xxdswup
- f487fe5e6c2298d5b2c55fe19f585cd8edd11658447286e98fa7a146dfe80950 http___doughdata.com_vbubkput29 [6]
- 83ef2110643ce33355f711c504611060fb0d743e2ea106693be9c4d0b3c90cc9 http___emdrozd.net_uwrecjic
- a2b5d0fe84fcc2d21e59d051f8afee62171d1a736d2bbfd00e9871a2cbc4a043 http___espansioneimmobiliare.com_zq6xw3mi3y
- fd0648f7e2af9b0b22fc6592cece14c4be18c76afaef4dda03669333b35e2194 http___fazendacristal.com_xcpidywxz
- 6283c966640460efa0c4ee74cb115a5226d9042fb23c0e235ae92fcae4a85d18 http___gerardfetter.com_vl8s7d0e
- 81dbbddf6c427cd64f4d3c1b0100c927030d245f53a4dda0dc81263b5f389270 http___grandfm.com_zlhmy4dq
- 29f43541021dd698cb9beea8e58431b0c5f69fb8d4ec7b8ab47256727e8dd3bb http___guymorgandaily.com_xjwgh [2]
- 637be0bfd4618fbfba15024c39ccf21fbf5df729df06eabb908878ee3a47ad2b http___hfhhk.com_xaox8be
- 47c68175a32018286d0831b51664c94bee8fee00088eb7708955210195f426b0 http___hosimin.com_l10nzv
- 29af183c15b27a697631ce70e3cee13c2e7042363f33dcfb6936a3da22cff0cf http___hubis.ir_cd2tvfn
- ad937024fab8a5eb20ab048c4eaa6b89fd2cd21019b60def39a3552cf02b50bc http___icnvcopa.com_byddwdjk
- 70a4494db2a649f6936220f89acc10d54ceaa65116c7db03f390b88fb92987b5 http___identita.dk_h0vxv8zxh
- 47557982b327cd3cd7f5cdfe3376228feda51ed2f1d6fddad26beebac3a19db7 http___iliebike.ro_ogqztl8
- 3cf4dc7d0e7f34a1305880c703e3fc6f4432e47e8ef17b58bfa10b691140c436 http___iluzja.pl_0byxmqj
- e6d7846070708485cb02c497c485da70f05259df2bd3bc024a2e750fc35ea464 http___indirimtakibi.com_17k5n
- 7c6be0cf81f2207741745b87b315b99395360f5dd86fe7a6b0a66bdbf8dedeb0 http___inspireyouths.org_tg3kzh
- 06680190d34f995cf2ed7ca5a4a3841c3ceddf135b41fcd94309eda1b1213e12 http___intensivo.nl_c1klzfc
- 5b380a3cd7f5a3a5b26abc6aa54376af55707a3b6b3ae751ac522ef9deada37f http___internationalservice.ro_leg893
- 7c45cfb9665f76c44b24a3ea614b04bad5afd95e98fc223e9d746c07acb541d6 http___ipiasarnano.it_cthwsd
- c43b6bdd54b09f50f1f0a3f5b363359af145e3d1635d9a1cd1cf0bc7def8f03a http___iptravel.net_5h63oeoy
- ea030cbb311979d840f266feaa14a77e6c733914f9696918aedcec548b38b931 http___irnetshop.com_dfvltrouq
- 643e8ccf8ed6aa27ade6518b330c396d231cba8a9988337aa84401c34a90859d http___i-school-tutor.com_3phcz44v
- 469122afca9f535d9e229790e6c8060aad68a541ea0ecbaaf0abe508e39d7e83 http___kexinbuy.com_q8rvf1dzxr
- 77fd9ce2d5ba3aa6832f100c27abc0dd174be0c19568255d07c8653a8b93b000 http___k-koubunsha.jp_5vb4zq
- 7de296a2077ebaef55249ab8fc6dffc12895e748bad1a821bd4a66e1d6feb49e http___kzprojekt.pl_hb3az2xwye
- 477b47bbfacbe82f08f1fd76c2e35e0ccd2766fa0bf6530499353221446e4ac9 http___lanehmontgomery.com_obqa0iwzj [1]
- fdd8bf39d5e0980f06c013b2c843cb9e760170a993480cb7ec9f7f6bd2280d87 http___langzhong8.com_bbxicl5h [5]
- be082d79284f5865c30969ffb9a8108c167ca8a7aca1d8b4c58960ddbd79221e http___laszloiparcikk.hu_fmgqm
- 13b1b9498e1239cb655c8495641295bfb0bdf711f9714f1e8a49b077346bb9b2 http___lihunyihou.com_qjc9vxc69
- 0343d830107b9fd0723c9a6d977d909d4cf0d941011ffe246e72b3a592b7829a http___lomtour.com_iziet4l3
- 17456ca41efd06c8baf8b1ff690f731e97ed18044369f18b327c92ba76de700c http___lvyeqingtian.com_auntes
- c1fbffccdd9c97163e475f7062045b0bf62845ae06566e4e67b38dcf9bedc72d http___manhtienphat.com_5ko2h
- 3efb883ccd841399f2787138da74ec867839c2360e67415d8d53583e8b4c5965 http___mice.co.th_n96w5nl8y7 [4]
- ac66fcd1589bfa7fbd971f710cfb3957dc43c0b9fa3bbdc12e3b8a5787c19c99 http___mildreddeskinsjewelry.com_itlgzij
- abcdc6fccc3fb8f52df03246e1b3f4f85a15c88c752b666eb4bcbb87605c6ee0 http___mileswebhosting.nl_0b0cyt
- 73bfc8e3e58a7ea3cc458101caa42d1e23df12a56410cfd7c4f8ee6b459a62ed http___moswomen.ru_ilteiri
- c412a98bc6a806fd11dcd4e67f304c6f35004269b926ad1cb62a8ccc5649e4de http___multicombs.com.au_fvmbusvz
- 67ee8c8e25a646f8640da3ff8488363cf1f81ef7dfc83351c116807ff5e2f178 http___mygfiltre.com_k8w97ku
- 8e294ef21824f95f10faa6e666bc6b33bdc322750c57c5841b243c75cfef7666 http___naturalcode-thailand.com_5py26ttl
- 00f44bb0cefe0b5660f9c4f3d71e202199766164f87579165c654346c0402b9f http___nnptrading.com_tbfr7
- c20b839424dc1e41b233d311059d83809790aa15a426c3998f49311edc48cb59 http___phaleshop.com_wpcnm4
- 5744e6c41586b2fa21d02f6f9f6dbd2bbf57b0c1824173063f1e11d05288a4a8 http___tafiathiol.net_19p1knzx
- 0f02254710286f0f186d2949978bfd1da31f365b0d5d520f5f35c390391278c9 http___tafiathiol.net_jxirmy
- 028c17cd6c66e1ec229e75380cb26e93cda840a57719eb01c4714c8893b5a400 http___tafiathiol.net_kebxo
- 842222b3d9fd1a9b46746708792e7c3274f446ac856462f487c3dcbe647fe72d http___tafiathiol.net_z3jo7fwzu
- 129b5761cfbdcc44788cc42ebc17d57dd4fe2b06033873cc9bb0ff536e1b2c09 http___tapersk.sk_vhu3cs5lf
- 5ef325ce390b6b85f32a41fe0fac7b9824780baa5a2d4a63c0ecda9584ccb897 http___tupsorva.net_9eytfon9 [3]
- 5901ff8659003524f79d7534ada7fa0cf29176647c27d1e385ea5b53e0f83efb http___tupsorva.net_db5z4a
- 2e19deb665591e99b6a8a78c4c94cba265b22c49a57cbeddb77983b8af1fd971 http___tupsorva.net_mzjlk
- 3de5e376ea0bc2b6de801bd7e31737337a1578517956ce33a4c48afb22f75a08 http___tupsorva.net_py6gfd
- c5c977ae292a35d5e8fab141a4fa78cd3daddfdca4d1aba8e86f35eddf54d7f6 http___vyingouch.com_9m0qcj
- ee94b6594ef8542f18c6a8ba21c9eadec11de2397945211c60b1faa1ef2e2f9f http___vyingouch.com_c0jnk6
- 3734a3132c466975e15a28efae36f28e72af25d57088d780e4108345b2b26ff2 http___vyingouch.com_hqeaas
- fae778bd4817a407912630b3cc2d63fc0fc656211203019adf8c7a00bde86be9 http___vyingouch.com_nseam1uiq
- 5d7ed96459ab54d4856b19e112df91b0c603d287c45e17b6e9c6a748481ffb74 http___www.dominoassociates.com_ysojeahx7t
- - decoded
- 27394c9b788ec784ce8a91922dcc8df10ac477c55ff0a54e31561bb9ec16a548 [1]
- 493cd254ed8c615e6776224ed47395a843e1a1681581dda8abb7cb7603c4b743 [2]
- a631b35a7c0e22aa4b41961af156c28693b49f6fde605efb569ac67dfaf9ed38 [3]
- 7b148054f7b4cca7a62b584051a7503b05baecfaf555f75ba4fa94561053f315 [4]
- 27e62fe1b81712e670d53c89a9efa2acb20c4435dc4da171e1c5b828e7020751 [5]
- 930c07c559386b26172cedc5739d8596231c49e46816950de46351c90a1db28d [6]
- - executed by "rundll32.exe %TEMP%\<dll_name>,oSFS"
- C2:
- POST http://213.32.66.16/information.cgi
- POST http://91.201.202.130/information.cgi
- POST http://95.213.186.93/information.cgi
- POST http://eoitfjhwkftjxnuax.xyz/information.cgi
- POST http://frlxomgynyrewlp.su/information.cgi
- POST http://hagjykjefuxpkmbgc.biz/information.cgi
- POST http://hnwndsekxujq.org/information.cgi
- POST http://kfddxkhlrlgtebjyq.pw/information.cgi
- POST http://kobtjrfwvwksbnn.ru/information.cgi
- POST http://mhedsgwklsandm.info/information.cgi
- POST http://qpflnpogocdkgfi.org/information.cgi
- POST http://rgkkumpjxphe.click/information.cgi
- POST http://snshjrocbpo.ru/information.cgi
- POST http://vlvpkbioma.pl/information.cgi
- POST http://yasqujdmfvgjukv.info/information.cgi
Add Comment
Please, Sign In to add comment