Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-10-03: #locky email phishing campaign "Emailing - DOCNNN"
- Email sample:
- ---------------------------------------------------------------------------------------------------------------------
- From: LOUIE DINGSDALE <Louie0021@thedaviscompany.com>
- To: [REDACTED]
- Subject: Emailing - DOC845
- Date: Tue, 03 Oct 2017 18:54:14 +0300
- Hi
- See attachment
- Attachment: DOC845.7z -> PDF458.js
- ---------------------------------------------------------------------------------------------------------------------
- - subject is "Emailing - <PDF|DOC><3 digits>
- - attached file "<DOC|PDF><3 digits>.7z" contains file "<DOC|PDF><3 digits>.js", a JScript downloader which will download malware from:
- Download sites:
- http://420ent.com/uyitfu65uy
- http://acaciainvestigations.com/uyitfu65uy
- http://atez.vn/uyitfu65uy
- http://chimachinenow.com/uyitfu65uy
- http://dbatee.gr/uyitfu65uy
- http://eternallyclassicjewelry.com/uyitfu65uy
- http://linksoft.co.nz/uyitfu65uy
- http://matern-eger.de/uyitfu65uy
- http://mysushi.it/uyitfu65uy
- http://phmetreci.com/uyitfu65uy
- http://restaurantelburladero.com/uyitfu65uy
- http://runkel.com.mx/uyitfu65uy
- http://sabines-marmeladen.de/uyitfu65uy
- http://sancorbr.com.br/uyitfu65uy
- http://shanta.de/uyitfu65uy
- Updated:
- http://envi-herzog.de/uyitfu65uy
- http://ericajoy.com/uyitfu65uy
- http://placecomp.com/uyitfu65uy
- http://studioslefteris.gr/uyitfu65uy
- http://yoma888.com/uyitfu65uy
- Malware:
- - Locky ransomware, offline ykcol variant
- - SHA256: d57fbae4df7a967f388644f9abd118c1efe25d7d54e5d78d24355ced9d427f01, MD5: b75bd60dc3686fe62eb4a4a8372be966
- - VT: https://www.virustotal.com/file/d57fbae4df7a967f388644f9abd118c1efe25d7d54e5d78d24355ced9d427f01/analysis/1507046577/
- - HA: https://www.reverse.it/sample/d57fbae4df7a967f388644f9abd118c1efe25d7d54e5d78d24355ced9d427f01?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement