Racco42

2017-07-27 TrickBot "Documents from xxxxx"

Jul 27th, 2017
799
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2017-07-27: #TrickBot email phishing campaign "Documents from xxxxxxxx"
  2.  
  3. Stage2 download sites:
  4. http://baravellis.com/16
  5. http://florerialosjasminez.com/3
  6. http://morgoo.es/14
  7. http://urachart.com/27
  8. http://domnickhunterrl.com/34
  9. http://2arquitectura.es/2
  10.  
  11. Malware download sites:
  12. http://2mconf.com/fgh43g4234
  13. http://2-wave.com/fgh43g4234
  14. http://9ninewright.net/fgh43g4234
  15. http://aafkescreaties.nl/fgh43g4234
  16. http://abstonework.ca/fgh43g4234
  17. http://actt.gr/fgh43g4234
  18. http://adr-werbetechnik.de/fgh43g4234
  19. http://a-g.cc/fgh43g4234
  20. http://allmumsaid.com.au/fgh43g4234
  21. http://cantalooplingerie.co.uk/fgh43g4234
  22. http://carcompanysolutions.be/fgh43g4234
  23. http://caribbeanartproducts.com/fgh43g4234
  24. http://carnepregiata.com/fgh43g4234
  25. http://castillodepalazuelos.es/fgh43g4234
  26. http://catterydelacanaille.be/fgh43g4234
  27. http://cdvhr.org/fgh43g4234
  28. http://somersetautotints.co.uk/fgh43g4234
  29.  
  30. Malware:
  31. - encoded on download, SHA256 32a456d9993cda3f4c2fe22b06d7032f0a412ebbb4852478ecfc72174fde8521, MD5 04c500e322446814404a87b23130dc17
  32. - decode by XORing with "F00LJY67NQbT9PRIveMcxU1TWUHH407P"
  33. - decoded SHA256 7e8df24fe85b141e52bbce3a809b284337455f6e09b205ce7b4992e1b507611b, MD5 f9601665b4811d98ab7ac17a78314ed8
  34. - VT: https://www.virustotal.com/en/file/7e8df24fe85b141e52bbce3a809b284337455f6e09b205ce7b4992e1b507611b/analysis/1501166816/
  35. - HA: https://www.reverse.it/sample/7e8df24fe85b141e52bbce3a809b284337455f6e09b205ce7b4992e1b507611b?environmentId=100
RAW Paste Data