Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-12-13: #locky email phishing campaign "a picture for you"
- Email sample:
- ----------------------------------------------------------------------------------------------------------------------------------
- From: Ronda <Ronda.16@theroyalparadise.com>
- To: [REDACTED]
- Subject: a picture for you
- Date: Tue, 13 Dec 2016 19:56:58 -0300
- scanned
- Attachment: 2016-12-623875.zip -> 2016-12-11225.jse
- ----------------------------------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "a (image|photos|photo|picture) of you"
- - attached file "2016-12-<4-6 digits>.zip" contains file "2016-12-<4-7 digits>.jse", a JScript (plaintext .js, not encoded) downloader
- Download sites (actual URLs have suffix ?<random>=<random> which does not influence download):
- http://00005ik.rcomhost.com/knby545
- http://1smart.nu/knby545
- http://203kitchen.com/knby545
- http://87.244.17.86/knby545
- http://88.150.144.236/knby545
- http://94.127.33.126/knby545
- http://abogalalmotors.com/knby545
- http://accademiamoda.com/knby545
- http://aidhanlogistics.com/knby545
- http://arc.com.pk/knby545
- http://armcoinfrared.com/knby545
- http://aspirekitchens.in/knby545
- http://batchmiami.com/knby545
- http://blog.webskitters.com/knby545
- http://bobyfrancisandpradeep.com/knby545
- http://brandappz.com/knby545
- http://brinktest.com/knby545
- http://c2sexpress.net/knby545
- http://caribbeachresort.com/knby545
- http://charlesworth.com.ng/knby545
- http://crewclaims-lubpi.com/knby545
- http://davepotterhonda.com.au/knby545
- http://dedicateddevelopers.us/knby545
- http://detrust888.com/knby545
- http://discoveryourevent.com/knby545
- http://dmg-properties.com/knby545
- http://dolutesisat.com/knby545
- http://dominatetheplate.com/knby545
- http://easyfooty.com/knby545
- http://ecolelavasa.edu.in/knby545
- http://ecommercedevelopment.us/knby545
- http://empirek9.com/knby545
- http://empmon.com/knby545
- http://entelligy.com/knby545
- http://excellentiasacademy.org/knby545
- http://fortuneprixgroup.com/knby545
- http://fshr.al/knby545
- http://gopa1.ru/knby545
- http://inventionsteel.com/knby545
- http://investps.com.au/knby545
- http://jasonvergara.com/knby545
- http://joomlaexpertdeveloper.com/knby545
- http://jrgolfbuddy.com/knby545
- http://keshamrit.com/knby545
- http://liftaccessory.com/knby545
- http://lmprojekte.de/knby545
- http://maheshpunjabi.com/knby545
- http://MedicalIsraelTourism.com/knby545
- http://modelpayments.net/knby545
- http://namemychild.cn/knby545
- http://nbjzpx.com/knby545
- http://newdawnexperience.com/knby545
- http://nixvector.com/knby545
- http://oakridge-realty.com/knby545
- http://oualili.org/knby545
- http://pandoracharm.ru/knby545
- http://pattumalamatha.com/knby545
- http://payserairan.com/knby545
- http://p-g-a.org/knby545
- http://prc.ub.ac.id/knby545
- http://projectprocurement.com.au/knby545
- http://pst-oil.com/knby545
- http://radiantstars.org/knby545
- http://reviewprimer.com/knby545
- http://rkanswers.com/knby545
- http://rktest.net/knby545
- http://rndled.com/knby545
- http://robekadevelopment.com/knby545
- http://site4.pulusajans.com/knby545
- http://socialcampaigns.co.in/knby545
- http://swarbandh.com/knby545
- http://tcmrecipe.com/knby545
- http://thungchang.go.th/knby545
- http://tradium.com.mx/knby545
- http://trustcarts.com/knby545
- http://turningpointdigital.com/knby545
- http://uberrito.com/knby545
- http://ukinhub.com/knby545
- http://uscpl.net/knby545
- http://uygoman.com/knby545
- http://velociter.in/knby545
- http://vibrantdeal.com/knby545
- http://vintageprintable.com/knby545
- http://visbymaklarna.se/knby545
- http://winawoof.com/knby545
- http://wordpress-developer.us/knby545
- http://www.cameracontrol.com/knby545
- http://www.designdepot.in/knby545
- http://zarasresort.com/knby545
- http://zist-konkur.ir/knby545
- http://2picme.com/0h6br33
- http://aacom.pl/0h6br33
- http://aaryn.net/0h6br33
- http://abela.fr/0h6br33
- http://abogalalmotors.com/0h6br33
- http://alestes.hu/0h6br33
- http://alock.co/0h6br33
- http://banhang123.com/0h6br33
- http://billionsfamily.com/0h6br33
- http://brookstonemanuals.com/0h6br33
- http://clarkcomm.com-ext.com/0h6br33
- http://eastoncorporatefinance.com/0h6br33
- http://ebreckinteriors.com/0h6br33
- http://fiddlefire.net/0h6br33
- http://forexilla.ru/0h6br33
- http://galebtopola.com/0h6br33
- http://gallery.mohammadtarighi.ir/0h6br33
- http://ilasd.org/0h6br33
- http://inzt.net/0h6br33
- http://ivibohoc.url.ph/0h6br33
- http://kathymerrill.com/0h6br33
- http://kirulya.com/0h6br33
- http://knihovna-libeznice.hostuju.cz/0h6br33
- http://kserwis.pl/0h6br33
- http://kurou.bokunenjin.com/0h6br33
- http://k-wu.com/0h6br33
- http://lukepaige.com/0h6br33
- http://masonlodgestpeter.org/0h6br33
- http://medianisprint.com/0h6br33
- http://mgascca.com/0h6br33
- http://miki-bazar.cz/0h6br33
- http://minis2.com/0h6br33
- http://mprotectcorp.com/0h6br33
- http://msveletiny.cz/0h6br33
- http://nortra-cables.com/0h6br33
- http://otteryak.de/0h6br33
- http://pcflame.com.au/0h6br33
- http://pta-babel.net/0h6br33
- http://qe7.ca/0h6br33
- http://rdsc-seminar.com/0h6br33
- http://s393640255.onlinehome.us/0h6br33
- http://s435378127.online-home.ca/0h6br33
- http://s437702314.onlinehome.us/0h6br33
- http://shomesofa.com/0h6br33
- http://stoneofliberty.com/0h6br33
- http://taladm.ru/0h6br33
- http://thomas-christ.de/0h6br33
- http://ulli-greve.de/0h6br33
- http://v-english.com/0h6br33
- http://vivvn.com/0h6br33
- http://worldhost1.com/0h6br33
- http://www.agence-eclectik.fr/0h6br33
- http://www.dazzle-events.be/0h6br33
- http://www.enhansit.com/0h6br33
- http://www.lauraleedonnelly.com/0h6br33
- http://www.mywoc.ca/0h6br33
- http://www.ninthdistrict.org/0h6br33
- http://www.servipisos.com.ar/0h6br33
- http://www.sitivisibili.it/0h6br33
- http://www.socialmediaplanner.com.au/0h6br33
- http://www.thepasobueno.com/0h6br33
- http://www.tourist-car.ru/0h6br33
- http://yellowstudio.pl/0h6br33
- UPDATE:
- http://akida.com/0h6br33
- http://archibaldmicrobrasserie.ca/0h6br33
- http://calderon.com.mx/0h6br33
- http://easylation.com/0h6br33
- http://promgazenergo34.ru/0h6br33
- Malware:
- - encoded on download
- SHA256 a9478cfd511672b5ad8c39212d848d8ff12fd2dd437c9c3b765da7604084b359, MD5 41eb243c2775c74519f1643c871ef161 [knby545]
- SHA256 a6c2328b3807596f3199ec2db3e1463e13e979f75829ba73dd98a414493f9d3c, MD5 c951ecd088e3a043a0db6d60914adc14 [0h6br33]
- - decoded
- SHA256 fd33604dd1a4ccc3a3779b5769f5fbb58754a1f9152a72323ca6ebdc5d8d98b9, MD5 6534795c6f0ffb3835a1828abce36f88 [knby545]
- SHA256 9ce472a78b91fd79c707c090cb6cf49a4b0a0df5e50d31409346528b2fb2db7a, MD5 d0d014659cb27cb67b83eef360d3c39f [0h6br33]
- - executed by
- "rundll32.exe %TEMP%\<dll_name>,get_value" [knby545]
- "rundll32.exe %TEMP%\<dll_name>,set_value" [0h6br33]
- - samples
- https://www.virustotal.com/file/fd33604dd1a4ccc3a3779b5769f5fbb58754a1f9152a72323ca6ebdc5d8d98b9/analysis/1481672421/ [knby545]
- https://www.virustotal.com/file/9ce472a78b91fd79c707c090cb6cf49a4b0a0df5e50d31409346528b2fb2db7a/analysis/1481672458/ [0h6br33]
- C2:
- POST http://176.121.14.95/checkupdate [knby545],[0h6br33]
- POST http://185.117.72.105/checkupdate [knby545],[0h6br33]
- POST http://193.124.185.187/checkupdate [0h6br33]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement