Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-08-08 #locky email phishing campaign "988g765f"
- Email sample (sender domain is same as recepients, subject varies; begins with Emailing, Attached, Copy or File):
- -----------------------------------------------------------------------
- From: "Dolly" <Dolly23@[REDACTED]>
- To: [REDACTED]
- Subject: Copy: Photo(61)
- [NO EMAIL BODY]
- -----------------------------------------------------------------------
- Attachment: "Photo(61).zip", containing "PictureXXX.wsf"; a JScript downloader
- Download sites (actual download URL also coontains random suffix e.g. ?PaAuxNPFQdk=bSTvQC):
- http://alpeteglio.it/988g765f
- http://armada-kar.nichost.ru/988g765f
- http://books-bsu-pd.atspace.org/988g765f
- http://bork-sh.vitebsk.by/988g765f
- http://expresso-sf.com.br/988g765f
- http://haha8.web.fc2.com/988g765f
- http://j-morin.fr/988g765f
- http://juegos-sb.atspace.com/988g765f
- http://keramago.web.fc2.com/988g765f
- http://lunaparkperugia.it/988g765f
- http://meguriau.koiwazurai.com/988g765f
- http://nflfootballpool.ca/988g765f
- http://nikiforov.dax.ru/988g765f
- http://w47hqoozb.homepage.t-online.de/988g765f
- http://www.acansorga.it/988g765f
- http://www.azetapiemonte.it/988g765f
- http://www.giuni.it/988g765f
- http://www.gonimar.onored.com/988g765f
- http://www.lafoce-nonsolovino.it/988g765f
- http://www.luigi-varsalona.net/988g765f
- http://www.plancho.de/988g765f
- http://www.telsiel.com/988g765f
- http://www.www.www.www.lappeenrannankalevalaisetnaiset.net/988g765f
- http://yosi.sa-suke.com/988g765f
- http://zsnbystre.republika.pl/988g765f
- Added:
- http://allrinku.web.fc2.com/988g765f
- http://del-sieradz.neostrada.pl/988g765f
- http://jk1109.cafe24.com/988g765f
- http://pogotowie.pcserwis.c0.pl/988g765f
- http://fieldtennis.web.fc2.com/988g765f
- Added:
- http://optimaalopgewicht.nl/988g765f
- Added:
- http://meguriau.koiwazurai.com/988g765f
- http://www.pasquaautonoleggi.it/988g765f
- Malware:
- Encrypted: ce07b01c56c3a377e9a2cf8bf04d8741a4b10a926bdd536bbe28255627c97c7e
- Decrypted: a8538c61746c690fe5e91999533d68068db0dc16d6f24dc290e952f808262f4b
- https://www.reverse.it/sample/5ea729545359fe199a1ace2d525488c667b5c096f55838ef9a9eb8132936c4a7?environmentId=100
- C2s:
- 185.129.148.19:80/php/upload.php
- 91.219.28.66:80/php/upload.php
- (vkhfytd.xyz) 188.166.150.176:80/php/upload.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement