Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- #Pony
- TNT shipping invoice themed emails with the following as an attachment:
- File Name: TNT Original Invoice Receipt_pdf.gz
- MD5: 2E69213F821DADAEEC60899F97140382
- Contains:
- File Name: TNT Original Invoice Receipt_pdf.pif
- MD5: 3FD2A13C659EAF84BA1E2A63541560FB
- No listing on VT.
- Calls out to:
- veezer[.]club/kc3settings/settings/settings/settings/gate[.]php
- 70[.]39[.]232[.]160
- open dir at veezer[.]club/update (source: @JaromirHorejsi)
- also hosted at 70[.]39[.]232[.]160:
- klk[.]host
- svit-zer[.]com
- even more badness, check out their registrant emails.
- #Lokibot in the mix there as well.
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement