Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-07-31: #GlobeImposter email phishing campaign "Scanned image"
- Samples: 443
- Email sample:
- --------------------------------------------------------------------------------------------------------------------
- From: "Marcelo" <Marcelo-57@panjshir.com>
- To: [REDACTED]
- Subject: Scanned image
- Date: Tue, 01 Aug 2017 08:49:00 +0700
- Image data in PDF format has been attached to this email.
- Attachment: 20170801205148.zip -> 20170801866068.js
- --------------------------------------------------------------------------------------------------------------------
- - sender is random
- - subject is "Scanned image"
- - attached file "2017<0731 or 0801><6 digits>.zip" contains file "2017<0731 or 0801><6 digits>.js", a JScript downloader which will download malware from:
- Download sites (URL contains suffix ??<random>=<random> which does not influence the download):
- http://aimtravel.pl/a87hbn
- http://aitree.com/a87hbn
- http://bccapital.com/a87hbn
- http://camsexy.be/a87hbn
- http://dreamoneday.com/a87hbn
- http://edutechservices.in/a87hbn
- http://hpmanagement.de/a87hbn
- http://inoveinternet.com.br/a87hbn
- http://labettolasaigon.com/a87hbn
- http://mm7758.com/a87hbn
- http://nowo-tech.de/a87hbn
- http://petsplace.ca/a87hbn
- http://popprojects.com/a87hbn
- http://psynetwork.org/a87hbn
- http://quente.nl/a87hbn
- http://quicklookback.com/a87hbn
- http://samogonochka.net/a87hbn
- http://scapin.de/a87hbn
- http://sethiwriting.com/a87hbn
- http://showyourdeal.com/a87hbn
- http://slvideo.net/a87hbn
- http://snehil.com/a87hbn
- http://spinlock.info/a87hbn
- http://stillsmokin.bravepages.com/a87hbn
- http://szymanowicz.eu/a87hbn
- http://tbdexpress.com/a87hbn
- http://ttcpv.com/a87hbn
- http://urachart.com/a87hbn
- http://zabandan.com/a87hbn
- http://zubairfazal.com/a87hbn
- Malware (SmoakLoader which will download the GlobeImposter malware):
- - SHA256 fbb8676259d0562ce087a1677477b6b2dfbc07432e4269016456701eeabdc455, MD5 6d869b86fea803b79acedeec7d0b0952
- - VT: https://www.virustotal.com/en/file/fbb8676259d0562ce087a1677477b6b2dfbc07432e4269016456701eeabdc455/analysis/1501545240/
- - HA: https://www.reverse.it/sample/fbb8676259d0562ce087a1677477b6b2dfbc07432e4269016456701eeabdc455?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement