Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #2016-09-05 #locky email phishing campaign "copies"
- Email sample (sender varies):
- -------------------------------------------------------------------------------------------
- From: "Garfield Larsen"
- To: [REDACTED]
- Subject: copies
- Hi ec20ceef, Lana told me you have lost some of the last few months' utility bills.
- So, I am sending to you the copies saved in my computer. Let me know if I sent the right receipts.
- Best Regards,
- Garfield Larsen
- -------------------------------------------------------------------------------------------
- Attached file <random_hexachars>.zip contains "utility_bills_copies <8_random_hexachars>.js" a JScript downloader
- Download sites:
- http://bookinghotworld.ws/18p0no4e
- http://canonsupervideo4k.ws/1bcpr7xx
- http://canonsupervideo4k.ws/54m7lt3
- http://darkestzone2.wang/1i0i75gq
- http://darkestzone2.wang/7b5hft
- http://listofbuyersus.co.in/2kpzu
- http://listofbuyersus.co.in/jos0k
- http://tradesmartcoin.xyz/3o8pon
- http://tradesmartcoin.xyz/ncgpse
- http://videoconvertermac.in/4g9h2sv
- http://videoconvertermac.in/ofyvi52b
- Malware encoded on donwload, filesizes 161796 and 162308 bytes
- 51abf331af1f4a6eb6d02cafee4f5f3cfb27256234cffa06a6c772e53757b6bc http___bookinghotworld.ws_18p0no4e
- 497461f4fefc4faab3ffb8e10f7371b45f2351d87cc28a626efda3adf5d88602 http___canonsupervideo4k.ws_1bcpr7xx
- 5072cfddb4df47f5c2a19799098752b6da982ed4bab42eb082878a04c84e1c70 http___canonsupervideo4k.ws_54m7lt3
- fd72c798c438d882cae11a61ab1eb087ca5d413ca666bfa585f7ba6aa76ae38c http___darkestzone2.wang_1i0i75gq
- 85ba61645e953e6124182e0716ea29824cd292fc6b060f728eefae662a6bc65a http___darkestzone2.wang_7b5hft
- df60ea23ff8af15221b063e53fa907a221b8836f03fe30a32b3103bf96083dcd http___tradesmartcoin.xyz_3o8pon
- 0cf5064b105dec0425bbf74a9825f83c17497f04ae27ce5a398fee52450377f2 http___tradesmartcoin.xyz_ncgpse
- https://www.reverse.it/sample/645d9767468248c291747dbf4f62bccf33a33f61e71298190b93177e780579e6?environmentId=100
- https://www.reverse.it/sample/81d65fc0505daacc9669c569297593e5dfeb5e937e95570225864a7037a0160e?environmentId=100
- https://www.reverse.it/sample/c1d7d0fef20909ca5b312058cd39963e08da2a7a85f87a377f38571cee07a2e4?environmentId=100
- https://www.reverse.it/sample/3fe75bd7f7f5737ec287284c97c5a91ef8420f99cc763bfb328e3512ad97aa06?environmentId=100
- https://www.reverse.it/sample/5543c09ffc47514709752f4dbee05e7d4b27155290007eb33c5c9a9db46e8a9f?environmentId=100
- C2:
- 158.255.6.109:80/data/info.php
- 185.154.15.150:80/data/info.php
- 185.162.8.101:80/data/info.php
- 91.211.119.71:80/data/info.php
- tqvaxumrdbhshcfrd.pw/data/info.php [95.211.174.92]
- uxfpwxxoyxt.pw/data/info.php [188.120.232.55]
Add Comment
Please, Sign In to add comment