Neonprimetime

Malicious Urls mods1401a.webcindario.com fetiche

Jun 20th, 2016
187
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.89 KB | None | 0 0
  1. Malicious Urls
  2. *******
  3. *******
  4. Email with ".z" file extension attachment
  5. Inside the ".z" was a ".jar" file
  6. Inside the ".jar" file executed Java code that downloaded these files and executed them.
  7. The files were then saved as
  8. c:\users\myname\mypcff.twerk
  9. c:\users\myname\mypctt.twerk
  10. c:\users\myname\mypc.twerk
  11. They were also executed with rundll32.exe
  12. *******
  13. hxxp://mods1401a.webcindario.com/fetiche/p64.png
  14. hxxp://mods1401a.webcindario.com/fetiche/pg.png
  15. hxxp://mods1401a.webcindario.com/fetiche/s64.png
  16. hxxp://mods1401a.webcindario.com/fetiche/p32.png
  17. hxxp://mods1401a.webcindario.com/fetiche/pg.png
  18. hxxp://mods1401a.webcindario.com/fetiche/s32.png
  19.  
  20. *******
  21. *******
  22. *******
  23. More FROM @neonprimetime security
  24.  
  25. http://pastebin.com/u/Neonprimetime
  26. https://www.virustotal.com/en/USER/neonprimetime/
  27. https://twitter.com/neonprimetime
  28. https://www.reddit.com/USER/neonprimetime
Add Comment
Please, Sign In to add comment