Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-30 #locky email phishing campaign "Emailing - xxxxxxxxxxxx.pdf"
- Email:
- -------------------------------------------------------------------------------------------------------
- From: "marva wayles" <marva.wayles906@dhl.com>
- To: [REDACTED]
- Subject: Emailing - 250154628979.pdf
- Date: Fri, 30 Sep 2016 10:24:24 +0530
- Hi
- Jasper has asked me to forward you the finance documents.
- (Please see attached)
- Many Thanks
- Attachement: 250154628979.zip
- -------------------------------------------------------------------------------------------------------
- - sender email address is spoofed to look like email is coming from recipient's domain
- - subject is "Emailing - <random numbers>.pdf"
- - attached file "<12 random numbers>.zip" contains file <12 random numbers>.wsf, a JScript downloader
- Download sites (the actual URLs contains suffix ?<random>=<random> which does not influence download)
- http://alkfh.net/938fhnr3
- http://amerikanservisi.com/938fhnr3
- http://athomeyogi.com/938fhnr3
- http://autokover.ru/938fhnr3
- http://b2c-batteries.com/938fhnr3
- http://badimalik.com/938fhnr3
- http://banquetesycoctelesfsf.com/938fhnr3
- http://baomoji.com/938fhnr3
- http://bapfresno.org/938fhnr3
- http://bestsourcecode.com/938fhnr3
- http://bin47110.com/938fhnr3
- http://bjbdshw.com/938fhnr3
- http://bj-fzwb.com/938fhnr3
- http://bjjmmt.com/938fhnr3
- http://bncxwood.com/938fhnr3
- http://boothbabeswithbrainz.com/938fhnr3
- http://cangsu.net/938fhnr3
- http://chandigarhcabs.com/938fhnr3
- http://chinalindun.com/938fhnr3
- http://demo.website.pl/938fhnr3
- http://shuspong.com/938fhnr3
- Malware
- - encoded on download, SHA256 a00fe7ccfd2022919969426ba9f5741e94a64f2f62af7e49214ec8780111ac73, filesize 245760 bytes
- - decoded SHA256 64032e1d59af7a76c395e5d4c5a09850bb92c17248714cb277600446de773a25
- - executed by "rundll32.exe %TEMP%\<dll_name>,qwerty"
- - samples
- https://www.reverse.it/sample/41c116e6fea9a862b23da93b9716b4c774013f4f0ac55841643bd09d402a9079?environmentId=100
- https://www.reverse.it/sample/a018a1dc93a017beb0fb3fdb95d97fadebdc5b2ec58439c5031195fe74691459?environmentId=100
- https://www.reverse.it/sample/8348b81913af56608fcec8c2c364de1a8b7f38b41561af26c6d4992526b33d5a?environmentId=100
- https://www.reverse.it/sample/7a9270925b8d4fbfde22b334f9c343d9ca475f7209a496bd23edffd4079fb499?environmentId=100
- https://www.reverse.it/sample/ddca9a01b0f09f0947b5120e3c8e21b1ab3aa04a2c29de6132d3939abbf0918c?environmentId=100
- C2:
- POST 149.202.52.215:80/apache_handler.php
- POST akpmonvka.biz:80/apache_handler.php [185.43.4.143]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement