Advertisement
Racco42

2017-07-18 TrickBot "blank"

Jul 18th, 2017
2,031
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.12 KB | None | 0 0
  1. 2017-07-18 #trickbot email phishing campaign with empty subject
  2. Stats: 2200 emails, 26 unique donwloaders, 25 download sites, 1 malware
  3.  
  4. Email sample:
  5. ---------------------------------------------------------------------------------------------
  6. From: no-reply@broadway-inf.s-gloucs.sch.uk
  7. To: [REDACTED]
  8. Subject:
  9. Date: Tue, 18 Jul 2017 08:17:49 -0200
  10.  
  11. Your Payment is attached.
  12.  
  13. Attachment: doc00089338097365745041.zip
  14. ---------------------------------------------------------------------------------------------
  15. - from is no-reply@<spoofed domain>
  16. - subject is empty
  17. - attachment "doc<20 random digits>.zip" contains 2 files - "ATT0000<2 random digits>.txt" (just padding) and "doc<20-21 random digits>.vbs" which will download from:
  18.  
  19. Download Sites:
  20. http://cor-huizer.nl/56evcxv
  21. http://demelkwegtuk.nl/56evcxv
  22. http://dielandy-garage.de/56evcxv
  23. http://elateplaza.com/56evcxv
  24. http://emmerich-fischer.de/56evcxv
  25. http://giwss.com/56evcxv
  26. http://harmat.pt/56evcxv
  27. http://huntwebs.com/56evcxv
  28. http://kampvelebit.com/56evcxv
  29. http://kleintierpraxiskloten.ch/56evcxv
  30. http://lsity.ru/56evcxv
  31. http://mainlinecarriers.co.tz/56evcxv
  32. http://marcelrahner.com/56evcxv
  33. http://marylanddevelopers.in/56evcxv
  34. http://multielectricos.com/56evcxv
  35. http://ossowski-essen.de/56evcxv
  36. http://phoneting7.com/56evcxv
  37. http://pluzcoll.com/56evcxv
  38. http://projector23.de/56evcxv
  39. http://provisionbazaar.com/56evcxv
  40. http://rosaspierhuis.nl/56evcxv
  41. http://sudhirchaudhary.com/56evcxv
  42. http://sxxinheng.com/56evcxv
  43. http://tipografia.by/56evcxv
  44. http://trasheh.com/56evcxv
  45. http://vlc.cl/56evcxv
  46.  
  47. Malware:
  48. - encoded on download SHA256 89f984871f01faf4cefb5bc74786b79ec9f8371276c7e88a61ab43a76c55dfd5, MD5 b924f159ceac9540d7fee49d893b47e1
  49. - decode by XORing download with "pPsV3MkICYRC2rINL8kKL3GJczjHBidO"
  50. - decoded SHA256 4ac28bbfa2db1c230a18b95f488d94c719822dd17dd19feb31f3c620294f838c, MD5 7c584546be8087b3d62cb72d4cd536d6
  51. - VT: https://www.virustotal.com/en/file/4ac28bbfa2db1c230a18b95f488d94c719822dd17dd19feb31f3c620294f838c/analysis/
  52. - HA: https://www.reverse.it/sample/4ac28bbfa2db1c230a18b95f488d94c719822dd17dd19feb31f3c620294f838c?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement