SHARE
TWEET

2016-12-14 Locky "Attached document"

Racco42 Dec 14th, 2016 49 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2016-12-14: #locky email phishing campaign "Attached document"
  2.  
  3. Email sample:
  4. --------------------------------------------------------------------------------------------------------------
  5. From: canon@[REDACTED]
  6. To: [REDACTED]
  7. Subject: Attached document
  8. Date: Wed, 14 Dec 2016 07:51:45 -0700
  9.  
  10. Attachment: 7550_008.docm
  11. --------------------------------------------------------------------------------------------------------------
  12. - sender address is canon@<recipient's domain>
  13. - subject is "Attached document"
  14. - email body is empty
  15. - attached file "<4 digits>_<3-4 digits>.docm" is Microsoft Word file containing autoopening macro that will download malware
  16.  
  17. Download URLs, malware etc.. is same as in "Booking Confrmation" campaign http://pastebin.com/WTbhCvD0
RAW Paste Data
Top