Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-11 #locky email phishing campaign "Emailing: _xxxxx_xxxxx"
- Sample email:
- --------------------------------------------------------------------------------------------------------
- From: "Deangelo" <Deangelo.edmondson0@promotive.net>
- To: [REDACTED]
- Subject: Emailing: _9097097_27631
- Date: Fri, 11 Nov 2016 21:48:42 +0530
- Your message is ready to be sent with the following file or link
- attachments:
- _9097097_27631
- Note: To protect against computer viruses, e-mail programs may prevent
- sending or receiving certain types of file attachments. Check your e-mail
- security settings to determine how attachments are handled.
- Attached: "_9097097_27631.zip"
- --------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Emailing: _<digits>_<digits>
- - attached file "_<digits>_<digits>.zip" contains file "_<digits>_<digits>.js", a JScript downloader
- Download sites (actual URLs have suffix ?<random>=<random> which does not influence the download):
- http://3.ihenan.com/487ygfh
- http://asrcargo.ru/487ygfh
- http://canidtrove.net/487ygfh
- http://house-of-quality.com/487ygfh
- http://hpdnet.com/487ygfh
- http://iarelative.com/487ygfh
- http://ibluegreen.com/487ygfh
- http://imckart.com/487ygfh
- http://inedinburgh.com/487ygfh
- http://ingservice.ro/487ygfh
- http://inspire-consultants.com.my/487ygfh
- http://itemweb.fr/487ygfh
- http://itrechtsanwalt.at/487ygfh
- http://jerabel.net/487ygfh
- http://jinghaishipin.com/487ygfh
- http://jndszs.com/487ygfh
- http://jobgroup.it/487ygfh
- http://jsharvie.com/487ygfh
- http://jsydjc.com/487ygfh
- http://jumeioo.com/487ygfh
- http://juran.pl/487ygfh
- http://jyxiangqin.com/487ygfh
- http://karayurt.nl/487ygfh
- http://kreanova.fr/487ygfh
- http://landauglobal.co.uk/487ygfh
- http://laundryonwheels.ca/487ygfh
- http://lightmusic.pl/487ygfh
- http://lingyuanbbs.com/487ygfh
- http://linneo.eu/487ygfh
- http://livinghealthyworld.com/487ygfh
- http://lkis.or.id/487ygfh
- http://lqbaihua.com/487ygfh
- http://lrbj.net/487ygfh
- http://lubrinor.pt/487ygfh
- http://magicaltouch.co/487ygfh
- http://malamalamak9.net/487ygfh
- http://marketingnatural.net/487ygfh
- http://mavisehirrotaract.org/487ygfh
- http://maximumauction.com/487ygfh
- http://mei-mei.jp/487ygfh
- http://mervereklam.com.tr/487ygfh
- http://midwaymetals.com.vn/487ygfh
- http://minglian.ca/487ygfh
- http://mohamedbelgaila.com/487ygfh
- http://project-group.pro/487ygfh
- http://relydorn.net/487ygfh
- UPDATED:
- http://luxurylivingph.com/487ygfh
- http://microcontroller-cafe.com/487ygfh
- Malware:
- - encoded on download, SHA256 e28d23886e3b62fb9109fd74b836f92fd3dee31471b41db3c60bbf4a18f830d3, MD5 0c166763d7342acc2a36f5168ed9a866
- - decoded SHA256 eb19e3967bca8a1e183aabb66684c97bc4798545e62d5ea51f57771af58f849a, MD5 844cd011920aa9d11b4ebbd4c800d2d8
- - executed by "rundll32.exe %TEMP%\<dll_name>,app"
- C2:
- POST http://107.181.174.34/message.php
- POST http://85.143.212.23/message.php
- POST http://86.110.117.244/message.php
- POST http://bnefhbdjcmsgv.info/message.php
- POST http://flljyguqfd.org/message.php
- POST http://hhhhjant.pl/message.php
- POST http://hiuswnvgggbh.xyz/message.php
- POST http://itupvhmnfieeqt.su/message.php
- POST http://mqhscwgej.su/message.php
- POST http://srdmhudpr.ru/message.php
- POST http://wigcemgwepq.work/message.php
- POST http://ynaqajdgxl.org/message.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement