Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-06 #locky phishing email campaign "Copy"
- Email sample:
- -----------------------------------------------------------------------------------------------------
- Subject: Copy
- To: Recipients <djijujpok@racco.cz>
- From: "Dana parkin" <Dana639@racco.cz>
- -----------------------------------------------------------------------------------------------------
- Attached file "payment slip <random_number>.zip" contains file "<random_number>.js"; however, the file is .hta file so it refuses to run. Othewise it would download malware from:
- Download sites (actual URLs contain ?<random>=<random> suffix, which has no impact on download):
- http://conserpa.vtrbandaancha.net/8976fyvgg
- http://daedalus.dommel.be/8976fyvgg
- http://dussartconsulting.com/8976fyvgg
- http://iesjaumei.edu.gva.es/8976fyvgg
- http://immobilien1000.de/8976fyvgg
- http://knochem.samsu.ru/8976fyvgg
- http://maxshoppppsr.biz/js/8976fyvgg
- http://propaganda.nichost.ru/8976fyvgg
- http://www.apmmc.it/8976fyvgg
- http://www.assonet.org/8976fyvgg
- http://www.caminettilcd.it/8976fyvgg
- http://www.carloabati.com/8976fyvgg
- http://www.csm94.org/8976fyvgg
- http://www.dondana.com/8976fyvgg
- http://www.francescafraioli.it/8976fyvgg
- http://www.hotelancorariviera.com/8976fyvgg
- http://www.ieslamerced.es/8976fyvgg
- http://www.leprimodels.it/8976fyvgg
- http://www.mussystems.net/8976fyvgg
- http://www.saumi.jazztel.es/8976fyvgg
- http://www.ussanlorenzo.it/8976fyvgg
- http://www.vanhoenacker.net/8976fyvgg
- Malware:
- Syntax error:
- https://www.reverse.it/sample/b9f15b930523ce2b6a61c51a764de2d2131d329034c63cfc79ba0eb377bf5de6?environmentId=100
- https://www.reverse.it/sample/85b2d4cfd4c19f018f00d5c563e3b6b3caa4bf2943494d15196811fa0942244c?environmentId=100
- https://www.reverse.it/sample/8cf5cca2095a1d675808a0c752bb2cfb20452e9ddb4250132614e7de76c14e57?environmentId=100
- https://www.reverse.it/sample/19f9608c0c21cac3bf74c6c9536d021a6049877b1c6cfc8fcdd1b6750269b65b?environmentId=100
- Fixed:
- https://www.reverse.it/sample/d95bc7a8be93c6c77914ea9229d4725422565d44df60e7818bd91085ca37f07b?environmentId=100
- https://www.reverse.it/sample/e439b075c2474591ec726b273dff243fd78fa6e7c075e68fdcb97bbd5771b6ae?environmentId=100
- decoded: SHA256 0f8163088cccb33ad415bd19b06aebe4cb26459c9529d455b01278e2b8f2fe75
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement