Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-08-09 #locky email phishing campaign "Documents Requested" / "09uh8ny"
- Email sample (recepient address is from the same domain as the sender; subject can also have RE: or FW: prefix):
- --------------------------------------------------------------------------------------
- From: "Marcelo"
- To: [REDACTED]
- Subject: FW: Documents Requested
- Dear [REDACTED]
- Please find attached documents as requested.
- Best Regards,
- Marcelo
- --------------------------------------------------------------------------------------
- Attachment "Untitled(06).docm", macro enabled MS Word document that downloads 2nd stage from:
- Download locations:
- http://flirtchat.atspace.com/09uh8ny
- http://jooob.web.fc2.com/09uh8ny
- http://rebolyschool.iso.karelia.ru/09uh8ny
- http://rot-solutions.com/09uh8ny
- http://rovd.vov.ru/09uh8ny
- http://sb-11037.fastdl-server.biz/09uh8ny
- http://stemnodig.dommel.be/09uh8ny
- http://teatrdomowy.republika.pl/09uh8ny
- http://user9749.vs.easily.co.uk/09uh8ny
- http://www.bogusleek.co.uk/09uh8ny
- http://www.cristinabertuzzi.com/09uh8ny
- http://www.fliegendergaertner.at/09uh8ny
- http://www.genonkoubou.jp/09uh8ny
- http://www.ibcresigum.it/09uh8ny
- http://www.ladylinetattoo.org/09uh8ny
- http://www.noema2k.it/09uh8ny
- http://www.prisma-srl.net/09uh8ny
- http://www.studiobrogi.com/09uh8ny
- http://www.weingut-ettenauer.at/09uh8ny
- Added:
- http://eleksanyi.home.ro/09uh8ny
- http://esvb.ru/09uh8ny
- http://fullbahis.atspace.com/09uh8ny
- http://www.falciano.it/09uh8ny
- Added:
- http://dnaproducoes.com/09uh8ny
- http://mesaia.ina-ka.com/09uh8ny
- http://tipstersplaza.web.fc2.com/09uh8ny
- http://used-alfaromeo-cars.co.uk/09uh8ny
- http://www.davidegallo.it/09uh8ny
- http://www.elektrykzyrardow.strefa.pl/09uh8ny
- http://www.nicolau11a-iasi.home.ro/09uh8ny
- http://radiodiscounters.com/09uh8ny
- http://www.csc-gauguin.fr/09uh8ny
- Malware encryped, filesize 278713 bytes
- Encrypted malware: ad62a6d0ed626c72135b75692cabe0c7a9b49a94be811678491a2a34a87af5ee
- https://www.reverse.it/sample/e38da18c6362c84f8869414fbcf7697719c3069800a216a26a9711045bd2caa7?environmentId=100
- https://www.reverse.it/sample/12c7443f5ca8f5a0bbcb39ed9f17744107cf4bf894a4c8d54ef3bb10ad041de4?environmentId=100
- https://www.reverse.it/sample/6b0c6268df147e846a15851ca30364ee960da486f685d9d344b3f876549548a7?environmentId=100
- C2s:
- 159.203.182.129:80/php/upload.php
- 185.129.148.19:80/php/upload.php
- (vkhfytd.xyz)188.166.150.176:80/php/upload.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement