Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-06-07 #thetrick email phishing campaign "nn_Invoice_nnnn"
- Email sample:
- ---------------------------------------------------------------------------------------------
- From: VICENTE GREAVE <vicentegreave@gentbrown.worldonline.co.uk>
- To: [REDACTED]
- Subject: 41_Invoice_5633
- Date: Wed, 7 Jun 2017 14:20:51 +0530
- 001_8966
- Attachment: 001_8966.pdf
- ---------------------------------------------------------------------------------------------
- Download Sites:
- http://1time.nl/7gyb3ds
- http://adproautomation.in/7gyb3ds
- http://aolongkeji.cn/7gyb3ds
- http://beursgays.com/7gyb3ds
- http://camberwellroofing.com.au/7gyb3ds
- http://caperlea.com/7gyb3ds
- http://castvinyl.ru/7gyb3ds
- http://choralia.net/7gyb3ds
- http://chqm168.com/7gyb3ds
- http://codeclinics.com/7gyb3ds
- http://essentialnulidtro.com/af/7gyb3ds
- http://luxcasa.pt/7gyb3ds
- http://manish-choudhary.com/7gyb3ds
- http://martos.pt/7gyb3ds
- http://micolon.de/7gyb3ds
- http://muldefischer.de/7gyb3ds
- http://musee-champollion.fr/7gyb3ds
- http://mybutterhalf.com/7gyb3ds
- http://mytraveltrip.in/7gyb3ds
- http://saheser.net/7gyb3ds
- http://sanftes-reiten.de/7gyb3ds
- http://shopf3.com/7gyb3ds
- http://shreekamothe.com/7gyb3ds
- http://spocom.de/7gyb3ds
- http://sumbermakmur.com/7gyb3ds
- http://surgideals.com/7gyb3ds
- http://suskunst.dk/7gyb3ds
- http://sutek-industry.com/7gyb3ds
- http://svagin.dk/7gyb3ds
- http://xinding.com/7gyb3ds
- Malware:
- - encoded on download SHA256 20b58891216e3393f2da7c470d5e6aaeeeafc7b97e20e16cd13d8d3d1f21800c, MD5 a4644ad54e4ff86a4a3479927857ac29
- - decode by XORing download with "HCbCpPsTQuiY5Acu4CqRGXWZnlCzdU2D"
- - decoded SHA256 79d96a62622e4efb01fda23cf81b759e0059ad3cd3083acff7fb4174b0b3d40c, MD5 9c6cecc960bfd950b64699b2fee1a723
- - VT: https://www.virustotal.com/en/file/79d96a62622e4efb01fda23cf81b759e0059ad3cd3083acff7fb4174b0b3d40c/analysis/1496825894/
- - HA: https://www.virustotal.com/en/file/79d96a62622e4efb01fda23cf81b759e0059ad3cd3083acff7fb4174b0b3d40c/analysis/1496825894/
- - config: https://pastebin.com/arUi7B1H
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement