Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-10-28: #locky email phishing campaign "DOC, FAX, IMG, SCAN"
- Email sample:
- ----------------------------------------------------------------------------------------------------------------------
- From: "Etta" <Etta74@[REDACTED]>
- To: [REDACTED]
- Subject: IMG_0069
- Date: Fri, 28 Oct 2016 11:13:12 -0500
- Attached: IMG_0069.zip
- ----------------------------------------------------------------------------------------------------------------------
- - email sender varies between emails, but sender domain is same as recipient's
- - subject of the email is "DOC_<number>", "FAX_<number>", "IMG_<number>", "SCAN_<number>"
- - body of the email is empty
- - attached file name "<%subject%>.zip" contains file "<%subject%>.wsf", a JScript downloader
- Download sites (the actuals URLs have suffix ?<random>=<random> which does not influence the download):
- http://00005ik.rcomhost.com/7fg3g
- http://104.131.83.218/7fg3g
- http://122.15.8.163/7fg3g
- http://1smart.nu/7fg3g
- http://2014.taktik-id.ch/7fg3g
- http://203kitchen.com/7fg3g
- http://2bconstruction.co.uk/7fg3g
- http://88.150.144.236/7fg3g
- http://94.127.33.126/7fg3g
- http://abn.info.ve/7fg3g
- http://accademiamoda.com/7fg3g
- http://ambrino.com/7fg3g
- http://arc.com.pk/7fg3g
- http://armcoinfrared.com/7fg3g
- http://armco-inspections.com/7fg3g
- http://artofovernight.com/7fg3g
- http://aspirekitchens.in/7fg3g
- http://autenticostacosdecanasta.com/7fg3g
- http://avnbiz.in/7fg3g
- http://batchmiami.com/7fg3g
- http://binarytradesignal.com/7fg3g
- http://blog.webskitters.com/7fg3g
- http://bptpm.sragenkab.go.id/7fg3g
- http://bpt.sragenkab.go.id/7fg3g
- http://brandactivators.be/7fg3g
- http://brinktest.com/7fg3g
- http://bruehwiler.ch/7fg3g
- http://caribbeachresort.com/7fg3g
- http://cemiselbiseleri.com/7fg3g
- http://charlesworth.com.ng/7fg3g
- http://chefsmart.com/7fg3g
- http://crewclaims-lubpi.com/7fg3g
- http://csrj-ah.rau.ro/7fg3g
- http://davepotterhonda.com.au/7fg3g
- http://dedicateddevelopers.us/7fg3g
- http://detrust888.com/7fg3g
- http://discoveryourevent.com/7fg3g
- http://dlmweddings.com/7fg3g
- http://dmg-properties.com/7fg3g
- http://dndwebtech.com/7fg3g
- http://dolutesisat.com/7fg3g
- http://dominatetheplate.com/7fg3g
- http://dotpixels.in/7fg3g
- http://ecolelavasa.edu.in/7fg3g
- http://ecolotienda.com/7fg3g
- http://ecommercedevelopment.us/7fg3g
- http://eipldevelopers.com/7fg3g
- http://empirek9.com/7fg3g
- http://empmon.com/7fg3g
- http://energiaadebate.info/7fg3g
- http://energietool.susteen.nl/7fg3g
- http://esnaftansatlik.com/7fg3g
- http://eurofruits.com/7fg3g
- http://excellentiasacademy.org/7fg3g
- http://fredandginger.com.au/7fg3g
- http://fshr.al/7fg3g
- http://givbee.com/7fg3g
- http://grandmar.nextmp.net/7fg3g
- http://hqunit.com/7fg3g
- http://innoservtest.in/7fg3g
- http://investps.com.au/7fg3g
- http://iridiumbox.com/7fg3g
- http://jasonvergara.com/7fg3g
- http://jobsdeed.com/7fg3g
- http://jrgolfbuddy.com/7fg3g
- http://keshamrit.com/7fg3g
- http://lmprojekte.de/7fg3g
- http://lolitojr.com.mx/7fg3g
- http://maheshpunjabi.com/7fg3g
- http://managedtech.net/7fg3g
- http://manuelcedeno.com/7fg3g
- http://meccinc.com/7fg3g
- http://metawellness.in/7fg3g
- http://mexusconsulting.com/7fg3g
- http://modelpayments.net/7fg3g
- http://mt-ph-champ.j-g.ch/7fg3g
- http://nationaltaxoffice.com/7fg3g
- http://palaschoga.com/7fg3g
- http://payserairan.com/7fg3g
- http://peggymurrahonline.com/7fg3g
- http://p-g-a.org/7fg3g
- http://primermundo.net/7fg3g
- http://pr.moi.go.th/7fg3g
- http://projectprocurement.com.au/7fg3g
- http://psagegenabsturz.de/7fg3g
- http://radiantstars.org/7fg3g
- http://rentadeplantaselectricas.com/7fg3g
- http://revistart.net/7fg3g
- http://robekadevelopment.com/7fg3g
- http://roommanageronline.com/7fg3g
- http://santtorre.com/7fg3g
- http://shreemahalaxmiagro.com/7fg3g
- http://site4.pulusajans.com/7fg3g
- http://skartusnea.net/7fg3g
- http://sne.bydgoszcz.pl/7fg3g
- http://socialcampaigns.co.in/7fg3g
- http://swarbandh.com/7fg3g
- http://tcmrecipe.com/7fg3g
- http://thingsandsuch.co.uk/7fg3g
- http://thungchang.go.th/7fg3g
- http://tradium.com.mx/7fg3g
- http://travellersstop.com/7fg3g
- http://turningpointdigital.com/7fg3g
- http://uscpl.net/7fg3g
- http://velociter.in/7fg3g
- http://vibrantdeal.com/7fg3g
- http://vintageprintable.com/7fg3g
- http://visbymaklarna.se/7fg3g
- http://vitasave.ca/7fg3g
- http://walkprint.com/7fg3g
- http://winawoof.com/7fg3g
- http://wordpress-developer.us/7fg3g
- http://www.designdepot.in/7fg3g
- http://www.kamakhyaits.com/7fg3g
- http://www.modwraps.com/7fg3g
- http://yellowbox.co.za/7fg3g
- http://yikson.com/7fg3g
- http://zarasresort.com/7fg3g
- http://zizicamarda.com/7fg3g
- Malware:
- - encoded on download, SHA256 19da9df3cde90416e64b9cee88df360cceb4dde4731d5bed9794f396d3322a24, filesize 237568 bytes
- - executed by "rundll32.exe %TEMP%\<dll_name>,EnhancedStoragePasswordConfig"
- - samples:
- https://www.reverse.it/sample/aeb6a2842628ffa6688fb7bde305ab00f4dc9e874f8d70865cc47545a0204839?environmentId=100
- https://www.reverse.it/sample/7575a384da1a464249cad3ac2cecc19e6435006ef5cd8a254cdbd490fa02ec0e?environmentId=100
- https://www.reverse.it/sample/6d8647d863c97b0347de9f08ff59499e077f010c8366d06abbae2610a66e1427?environmentId=100
- https://www.reverse.it/sample/2aa1228400c0e71cda456e1c31668dec8eadf3938819509d318e1cb2077d7088?environmentId=100
- https://www.reverse.it/sample/a71005d497d227e95968b3cd10f6172aca5d53782a9957b4662445fda5e2fe93?environmentId=100
- https://www.reverse.it/sample/d426eec3089c6193623f60df1b8f5d454a48a0648fdc85b331ae4397b2aa747b?environmentId=100
- https://www.reverse.it/sample/046605902ae8466d90948d54ac571295a359f8a2dc70fbdbd29d87c03d1196d4?environmentId=100
- C2:
- POST 91.107.107.241:80/linuxsucks.php
- POST 46.148.26.99:80/linuxsucks.php
- POST uxpxpirusm.xyz:80/linuxsucks.php [192.42.116.41]
- POST qggdljlijbygeutc.click:80/linuxsucks.php [192.42.116.41]
- POST pqrifsjpryygmip.pw:80/linuxsucks.php [192.42.116.41]
- POST wbaskcsxiffiax.info:80/linuxsucks.php [69.195.129.70]
- POST fpeuwdde.xyz:80/linuxsucks.php [192.42.116.41]
Add Comment
Please, Sign In to add comment