Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2015-10-03 #locky email phishing campaign "please sign"
- http://blog.dynamoo.com/2016/10/malware-spam-please-sign-leads-to-locky.html
- Email:
- --------------------------------------------------------------------------------------------------------------------
- From: "Otha Hampton" <Hampton.1571@berlin-girls.de>
- To: [REDACTED]
- Subject: please sign
- Date: Mon, 03 Oct 2016 15:34:38 +0530
- Hi [REDACTED],
- I have made the paperwork you asked me to prepare two days ago.
- Please check the attachment. It just needs your signature.
- Best Wishes,
- June Odom
- Key Account Director Municipalities
- Attachment: paperwork_scan_003e18766.zip
- --------------------------------------------------------------------------------------------------------------------
- - sender address varies between emails
- - subject is "please sign"
- - attached file "paperwork_scan_<random hexa chars>.zip" contain two files - one-letter-named junk file and file "paperwork scan ~<random hexa chars>.wsf", a JScript downloader
- Download sites:
- http://charge2go.com/coplbr
- http://dangras.net/3geg2zj
- http://dangras.net/5edbite
- http://dangras.net/6lebt
- http://dotcom-enterprises.com/cpgskvx9
- http://eskrow.ru/gk2sabe
- http://ferumusky.com/229k9z
- http://ferumusky.com/5o11b5s
- http://ferumusky.com/6nfhu0lt
- http://galelaure.com/gvn4j9eq
- http://honeine.com/h03dyzp
- http://joplinglobeonline.com/cc3al2x7
- http://louisirby.com/cmlfoyb
- http://louisirby.com/ejtocks
- http://medicangka.com/2wn3r
- http://medicangka.com/515grm
- http://medicangka.com/65l4byy
- http://mucicsitta.net/2imhkap
- http://mucicsitta.net/4li3zc
- http://mucicsitta.net/64vvi
- http://mutiarafurniture.com/qwal3v9
- http://ossiatzki.com/dyke9
- http://p2pbikini.com/cm9s56to
- http://parasaymamakina.net/ja152
- http://relianceclouds.com/tr56dz8z
- http://rondeaho.com/08dqn
- http://rondeaho.com/24agob
- http://shinipri.com/brzvbi
- http://softwaregolower.com/rddt0z
- http://syncfish.com/k7brjhgm
- http://tandjsalon.com/gd5ke
- http://welsell.com/tgtmzm
- Malware:
- - encoded on download, filesize 163332
- 557ecdd50394a5d7f8c4ab8a601181daab05c546ad1f46f7e0b1e2ecfdc8774b http___charge2go.com_coplbr
- bbb7ddaa902d8b841fa61d19b1d660c700cafdec6b2d5e053869b013b748b730 http___dangras.net_3geg2zj
- dd08228c392f453fca3c2a7ce9704f459adfb877a11dc8678f28780c0b23b7a5 http___dangras.net_5edbite
- dc5af8dedfd5bfd7aba3835016b5c2dd0dedf32c9cd573f87821d4b874bce334 http___dangras.net_6lebt
- b930bd9a83872fefd9f0998d68ba06bce89443fa0a4c53cccef43e54efe8bb29 http___dotcom-enterprises.com_cpgskvx9
- 980ec589d5235ceeddb6b9386104179dadd257e80f7b59b196d8b56e6b56bc1a http___eskrow.ru_gk2sabe
- 734f88817afd59964e6996a3adacc3578fbb9a2dfb521eb25b18dbc2dfe595b0 http___ferumusky.com_229k9z
- b101235e9d617498e55d40688ef4482d642ea93a8be9bca1139242582d14ec14 http___ferumusky.com_5o11b5s
- 3128acae30eb3bf5df2ac9c39ae852941002df4c9b8ad184954bbdedee22a72c http___ferumusky.com_6nfhu0lt
- 8eda605ee5f6dbfe29b651c1397e780f96d36e8fe837ac98cda677096fd026f0 http___galelaure.com_gvn4j9eq
- 5099475989f74f2106c2dcd383b47c086e582b980d9ce1c5c3eced8b856c2d26 http___joplinglobeonline.com_cc3al2x7
- f37ab2fbc3c42e0279640fccdcd08484e82c0ed22ed068d47ccc359ec8b8e644 http___louisirby.com_cmlfoyb
- 03d3c17961ef23246beb1ebac534605161b71a79238a64c7053e72b3c0d667a9 http___louisirby.com_ejtocks
- 98cf3234aee25840bc51d05ad5f66375dcab0efbb21cd08499a6ccc24aaeab56 http___medicangka.com_2wn3r
- e9547541475ebcd5dc4e5caad7d53e290a19fb91dabc796cc4d54432905d2284 http___medicangka.com_515grm
- 3d89cb66726cc219d7872bb6e00fa235c7c213b8a0331452be1ee2301dc00d84 http___medicangka.com_65l4byy
- 092bdbb596e756c0ec6e3066c3cbab489f63b5d4f3b0cf4851750a03066d0ba8 http___mucicsitta.net_2imhkap
- d0e8789f090b06d6698d07ca028bcf0185f94ebe0a85f9328392def67e16ec1b http___mucicsitta.net_4li3zc
- 779b65ccfb0b2c3b6659eef2cf1ed4146c1c67d47dc77c9732279544bb71a0e4 http___mucicsitta.net_64vvi
- 5f9088706a9742f6a238b6b2695d77b0f017dd4e9a666b84867a338d4003f427 http___mutiarafurniture.com_qwal3v9
- 09193a04a852092e71ac0dbdd285738b7c7ac399171cb8f8f8476c9c574e7327 http___ossiatzki.com_dyke9
- 43a0418eaceadbb8c03b5d720f7583a84cd5cf9f69bea33890dc64f938c4c8f5 http___p2pbikini.com_cm9s56to
- 7e916878f623f36cc7c9ad32b5cfdfadcde605d501d3cbc63f302945d15af1f8 http___parasaymamakina.net_ja152
- 6f39d179366181c7a6544229ba957ce5ec8736b20ff2adaa736490710a5a8595 http___relianceclouds.com_tr56dz8z
- a29969dda69ca58636f32ae66b5a3aa6a99812d09756ca0e471324c2769e69c9 http___rondeaho.com_08dqn
- ce347f56c824055c46bd6d17bcab3c091bb0d5bd74ce292653502987d5b660a9 http___rondeaho.com_24agob
- 1f2b542755531b5cb74863182f84b614903de8235bfb561e72b3c13541f77abf http___shinipri.com_brzvbi
- eb6c3d3cc394d41f5a46f7f0f78dc19e8df9afb2bce0496b7880ec551cfb7937 http___softwaregolower.com_rddt0z
- fa7df4fc07444b5e36dcba8c78d75ee4a38ac02c45549f55db283a31eae7c90c http___syncfish.com_k7brjhgm
- 54314bd371b53c2f2c7e9eb41970f231d82b871ca8bc74639c060c80bc7352cf http___welsell.com_tgtmzm
- - executed by "rundll32.exe <dll_name>,qwerty 323"
- - samples
- https://www.reverse.it/sample/2b3bfd64d9cba71141dbc927d68196252c338a5c061ae66a0536ede587633b61?environmentId=100
- https://www.reverse.it/sample/7619fd4ebf89030dc2da85906cd4eccc63422080c7ccb0a416f3acb932253e50?environmentId=100
- https://www.reverse.it/sample/75c64e65071345abd00bdad287d5d791526fc10ad0b56176617e0622afb76724?environmentId=100
- https://www.reverse.it/sample/7a19750588c3693657d8cf91fec57d01a7e31e65e5f17076cc16c94ad706345d?environmentId=100
- C2:
- - no C2 communication visible, offline variant
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement