Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-07: #locky email phishing campaign "Scanned image from MX2310U"
- Email sample:
- ---------------------------------------------------------------------------------------------------------------
- From: "office@[REDACTED]" <office@[REDACTED]>
- To: [REDACTED]
- Subject: Scanned image from MX2310U@[REDACTED]
- Date: Mon, 07 Nov 2016 13:43:48 -0200
- Reply to: office@[REDACTED] <office@[REDACTED]>
- Device Name: MX2310U@[REDACTED]
- Device Model: MX-2310U
- Location: Reception
- File Format: PDF MMR(G4)
- Resolution: 200dpi x 200dpi
- Attached file is scanned image in PDF format(RAR archive).
- Use Acrobat(R)Reader(R) or Adobe(R)Reader(R) of Adobe Systems Incorporated to view the document.
- Adobe(R)Reader(R) can be downloaded from the following URL:
- Adobe, the Adobe logo, Acrobat, the Adobe PDF logo, and Reader are registered trademarks or trademarks of Adobe Systems Incorporated in the United States and other countries.
- http://www.adobe.com
- Attachment: "office@[REDACTED]_20161107_134348.zip"
- ---------------------------------------------------------------------------------------------------------------
- - sender address is office@<recipient's domain>
- - subject is "Scanned image from MX2310U@<recipient's domain>
- - attached file "office@<recipeint's domain>_20161107_<6 digits>.zip" contains file "<3 uppercase chars><5 digits>-<4 digits>.js", a JScript downloader
- Download sites (actual URLs contain suffix ?<random>=<random> which does not influence download):
- http://365aiwu.net/hgf65g
- http://adriandomini.com.ar/hgf65g
- http://agorarestaurant.ro/hgf65g
- http://anagrual.es/hgf65g
- http://arrefrigeracao.com.br/hgf65g
- http://arxaggelos.com/hgf65g
- http://asiawing.com/hgf65g
- http://asirio.es/hgf65g
- http://atforum.pl/hgf65g
- http://avon2you.ru/hgf65g
- http://ayurvedic.by/hgf65g
- http://bajkowedekoracje.pl/hgf65g
- http://bappeda.palangkaraya.go.id/hgf65g
- http://beautyexpress.com.au/hgf65g
- http://bielpak.pl/hgf65g
- http://bogaziciradyo.com/hgf65g
- http://casaxavier.com.mx/hgf65g
- http://certop.hu/hgf65g
- http://chandrphen.com/hgf65g
- http://cheedellahousing.com/hgf65g
- http://chinaeyes.net/hgf65g
- http://city-hospital.com/hgf65g
- http://comovan.t5.com.br/hgf65g
- http://corinnenewton.ca/hgf65g
- http://cozyculmy.com/hgf65g
- http://dannyvanleeuwen.nl/hgf65g
- http://diandiandx.com/hgf65g
- http://drmulchandani.com/hgf65g
- http://dtfxggsc.com/hgf65g
- http://dwcell.com/hgf65g
- http://dzwiekowe.com/hgf65g
- http://edubit.eu/hgf65g
- http://efabryka.net/hgf65g
- http://eldamennska.is/hgf65g
- http://eribusiness.com/hgf65g
- http://eroger.be/hgf65g
- http://esustentables.com.ar/hgf65g
- http://fashioncheer.com/hgf65g
- http://fibrotek.com/hgf65g
- http://flirtkurs.ch/hgf65g
- http://freemailguide.com/hgf65g
- http://frejasvej.dk/hgf65g
- http://frumiel.cl/hgf65g
- http://furniturefactory.lk/hgf65g
- http://g2cteknoloji.com/hgf65g
- http://g2el.com/hgf65g
- http://ge3epmup.ru/hgf65g
- http://geist.fr/hgf65g
- http://gerardfetter.com/hgf65g
- http://gestuet-sterzer.de/hgf65g
- http://globalem.asia/hgf65g
- http://globissys.co.id/hgf65g
- http://goedvanstart.nu/hgf65g
- http://gokmasan.com/hgf65g
- http://goldensad.ru/hgf65g
- http://gossipsjunction.com/hgf65g
- http://gpsoft.pl/hgf65g
- http://groundfloorelevator.com/hgf65g
- http://guusdam.nl/hgf65g
- http://hairflicksmodelphotography.co.uk/hgf65g
- http://hanami.cz/hgf65g
- http://happyhands.ru/hgf65g
- http://hayber.com/hgf65g
- http://henrytye.com/hgf65g
- http://hgssyouth.com/hgf65g
- http://hogsmeade.ru/hgf65g
- http://holmebjerg.dk/hgf65g
- http://magical-connection.com/hgf65g
- http://mospi.ru/hgf65g
- http://pillorydowncommercials.co.uk/hgf65g
- http://termoskan.ru/hgf65g
- http://tw.wapv.net/hgf65g
- UPDATED:
- http://bst.tw/hgf65g
- http://codanuscorp.com/hgf65g
- http://gruppoeslabon.com.ph/hgf65g
- http://gzzzsm.com/hgf65g
- http://happymedia.vn/hgf65g
- http://hjarne.dk/hgf65g
- http://m.geology.kg/hgf65g
- http://nsrcconsulting.com/hgf65g
- http://pastelesallegro.mx/hgf65g
- http://xiguacity.com/hgf65g
- Malware:
- - encoded on download, SHA256 e755250d252922ff8111d59c0cb929dc3933d57d4fa26ac542fca192285cb81b, MD5 d21cf8c4a6afe9ff540d94a4a78c1f4b
- - decoded SHA256 9ceca8d84f947b713910ce4b7a961e875e63284ca0f913bec845b65fedd4730f, MD5 b137f7d1acc5928664e2c5ae361be8df
- - executed by "rundll32.exe %TEMP%\<dll_name>,SetText"
- - samples:
- https://www.reverse.it/sample/42463692f4dba0a50fb1e457632295b83f829b413aef68f7e4f8ba533aec6317?environmentId=100
- https://www.reverse.it/sample/e74efba840482806095911cc907d0694f2ac8c9c1b76cbf9ae5d9e95388b8554?environmentId=100
- https://malwr.com/analysis/ZjNlNWY0Y2UwMmZlNDc2N2FjNzdkZDU2OTM1NTZmYjM/
- C2:
- POST 81.177.27.222:80/message.php
- POST 176.103.56.120:80/message.php
- POST 81.177.180.53:80/message.php
- akufldsjlcyntbtq.biz
- pdqgefjnekpydy.su
- cscdomk.ru
- gowcifwxytc.biz
- xcvrhfingmenyt.su
- thexaiugfckdpdr.ru
- sfsljbulrimpk.su
- upepdgqcxrtsjxu.pw
- bappeda.palangkaraya.go.id
- kcjgdxep.pw
- rqppmufvesfrs.org
- fwyecrapmwiescamb.info
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement