Racco42

2016-11-08 Locky "Statement"

Nov 8th, 2016
3,616
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.01 KB | None | 0 0
  1. 2016-11-08 #locky email phishing campaign "Statement"
  2.  
  3. Email sample:
  4. -------------------------------------------------------------------------------------------------------
  5. To: [REDACTED]
  6. Subject: Statement
  7. Date: Tue, 08 Nov 2016 13:34:17 +0330
  8.  
  9. For your Information.
  10.  
  11. Attachment: "Statement PDF - 51707599835.zip"
  12. -------------------------------------------------------------------------------------------------------
  13. - sender address is "accounts@<random domain>"
  14. - subject is "Statement"
  15. - attached file "Statement PDF - <random numbers>.zip" contains file "<3 letters><5-6 digits>-<4 digits>.wsf", a JSCript downloader
  16.  
  17. Download sites (actual URLs contain suffix ?<random>=<random> which does not influence download):
  18. http://alamanconsulting.at/67j5hg
  19. http://all-kaigo.com/67j5hg
  20. http://arabom.com/67j5hg
  21. http://bmkgjateng.com/67j5hg
  22. http://dhmodel.cz/67j5hg
  23. http://fitnessrelax.sk/67j5hg
  24. http://focovi.cl/67j5hg
  25. http://frivill.hu/67j5hg
  26. http://fsgbly.com/67j5hg
  27. http://fu-k.jp/67j5hg
  28. http://fulltattoo.com/67j5hg
  29. http://fungasoap.net/67j5hg
  30. http://futurovision.com/67j5hg
  31. http://g2m.pl/67j5hg
  32. http://gaestehaus-kellner.de/67j5hg
  33. http://galebtopola.com/67j5hg
  34. http://gambit.nysa.com.pl/67j5hg
  35. http://gentscha.de/67j5hg
  36. http://geodispo.com/67j5hg
  37. http://giasungoaingu.net/67j5hg
  38. http://gigabothosting.com/67j5hg
  39. http://gingell.ca/67j5hg
  40. http://giochasach.com/67j5hg
  41. http://gisinecology.com/67j5hg
  42. http://glassfusing.com.au/67j5hg
  43. http://golden-bereg.ru/67j5hg
  44. http://gpstrackerbali.com/67j5hg
  45. http://grafa.cz/67j5hg
  46. http://grahamkennedy.ca/67j5hg
  47. http://greatmeeting.org/67j5hg
  48. http://greenmodul.com/67j5hg
  49. http://greenoceanpetroleum.com/67j5hg
  50. http://greentic.univcasa.ma/67j5hg
  51. http://grplink.com/67j5hg
  52. http://guneynakliyat.net/67j5hg
  53. http://gushifengyun.com/67j5hg
  54. http://gxhedu.net/67j5hg
  55. http://hamburyhird.co.uk/67j5hg
  56. http://hamidrukkers.nl/67j5hg
  57. http://hanak-nafotil.kvalitne.cz/67j5hg
  58. http://haneyslanding.com/67j5hg
  59. http://happyrushop.com/67j5hg
  60. http://havaa.nl/67j5hg
  61. http://hcunit.com/67j5hg
  62. http://helfter.fr/67j5hg
  63. http://hgqcqc.com/67j5hg
  64. http://highlandsolar.ca/67j5hg
  65. http://hightradingfrequency.com/67j5hg
  66. http://hirdavatix.com/67j5hg
  67. http://h-miyoshi.ed.jp/67j5hg
  68. http://hobbis.cz/67j5hg
  69. http://hubbambaya.net/67j5hg
  70. http://interprofil.no/67j5hg
  71. http://inzt.net/67j5hg
  72. http://iwebsdns.com/67j5hg
  73. http://kekjacint.hu/67j5hg
  74. http://kongogene.com/67j5hg
  75. http://monowheels.ru/67j5hg
  76. http://omidak.ir/67j5hg
  77. http://restaurant-traditional.ro/67j5hg
  78. http://shopey.net/67j5hg
  79. http://vikingradom.freehost.pl/67j5hg
  80. http://wilson.ro/67j5hg
  81.  
  82. UPDATE:
  83. http://fourpair.com/67j5hg
  84. http://gomuskegon.mobi/67j5hg
  85. http://gremr.ma/67j5hg
  86. http://sungbocne.com/67j5hg
  87.  
  88. UPDATE:
  89. http://chuzhang.net/67j5hg
  90. http://cxsd.com.cn/67j5hg
  91. http://funkybytes.fr/67j5hg
  92. http://funtasy.be/67j5hg
  93. http://futureartdesign.ro/67j5hg
  94. http://gocascadia.com/67j5hg
  95. http://goldensail.ru/67j5hg
  96. http://gold-or.ca/67j5hg
  97. http://mgpu.gomel.by/67j5hg
  98.  
  99.  
  100. Malware:
  101. - encoded on download, SHA256 da490b31aea1775216e95c036a311dd56cad99f8848230caaf89d7450a5471a3, MD5 4164b4a9b8a8c3bfc0effd3b7dbfd6f7
  102. - decoded SHA256 7e6c08f576eeef7c44558fdfc8c6961de15d16d15ab5cf8615951084a5960007, MD5 ed5eee4f7d209413bc8ef139f448e12d
  103. - executed by "rundll32 %TEMP%\<dll_name>,set"
  104. - samples:
  105. https://www.reverse.it/sample/44f87f0bafd325e02655b6f407df3656d59b762acf02ef1178f828d7d2c9b0f0?environmentId=100
  106. https://www.reverse.it/sample/025a3e2f1ccbd10cbce15ab84ba91a029930e2ea5d3c9ab217a8cfe1f2168638?environmentId=100
  107. https://www.reverse.it/sample/ab097596e05ab96cf484a15f3eed0d687a042a949a5bf2af66dbca72dc29f776?environmentId=100
  108. https://www.reverse.it/sample/0732a12bff0b1985bdaf322fb00345680bd1ff8f7babb6c2ad8b6d0ca987acfd?environmentId=100
  109.  
  110. C2:
  111. POST http://158.69.223.5/message.php
  112. POST http://185.118.66.90:80/message.php
  113.  
  114. bnmqkgdlotrwqym.work
  115. dmynnrrvse.org
  116. gccaoqb.xyz
  117. jcbbccd.pl
  118. ksrcvmvfbc.org
  119. ornrkiokjkkqymw.org
  120. mwyryuxoyhxlk.work
  121. ummprtrxunm.xyz
  122. wmstntaae.su
  123. wmcrfvhf.org
Advertisement
Add Comment
Please, Sign In to add comment