Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-08-30 #locky email phishing campaign "FW: [Scan] 2016-08-13"
- Email sample
- - the sender address varies and is faked to be from recipient's domain;
- - date in email subject is same, but time varies;
- - the message looks "forwared" (thus the Original Message header)
- ---------------------------------------------------------------------------------------------------------
- From: "Rodrick" <Rodrick888@[REDACTED]>
- To: [REDACTED]
- Subject: FW: [Scan] 2016-08-13 13:38:18
- -----Original Message-----
- From: "Rodrick" <Rodrick888@[REDACTED]>
- Sent: 2016-08-13 13:38:18
- To: [REDACTED]
- Subject: [Scan] 2016-08-13 13:38:18
- --
- Sent with Genius Scan for iOS.
- http://bit.ly/download-genius-scan
- ---------------------------------------------------------------------------------------------------------
- Attachment: file "2016-08-30 [XX] [YY] [ZZ].zip" containing file "[random chars].hta" which contanins JScript downloader
- Download sites (actual URLs have suffix ?<random>=<radnom>, but it does not influence the downloaded code):
- http://alc-okadakogyo.com/HJghjt872
- http://a-tconsulting.co.uk/HJghjt872
- http://csmwwst.de/HJghjt872
- http://detoxshop.atspace.com/HJghjt872
- http://jack0v0.web.fc2.com/HJghjt872
- http://pcps.web.fc2.com/HJghjt872
- http://powermax.ru/HJghjt872
- http://rakutenjapan.web.fc2.com/HJghjt872
- http://w07q93g5g.homepage.t-online.de/HJghjt872
- http://www.avisgibellina.it/HJghjt872
- http://www.download.extraslot.ru/HJghjt872
- http://www.fmpromedia.com/HJghjt872
- http://www.hager.50webs.org/HJghjt872
- http://www.helpinict.co.uk/HJghjt872
- http://www.itogazaidan.jp/HJghjt872
- http://www.redanchemical.com/HJghjt872
- Malware
- - encoded during download, SHA256 7ee7af0eee7ecb8e025533677e51065944e44ec6666c10bb85f09671ef62debc, filesize 143360 bytes
- - decoded SHA256 db74ae79244ee9c1db11c1d107a95d59258091c1239a318586a56e10b7a89571
- https://www.reverse.it/sample/1a16ab54dd193db81ae3b9d80e37966c5321a5b33ec3dfb8a40c6548822ab472?environmentId=100
- https://www.reverse.it/sample/f4ca63a30d0ba9a056a20b66e03d59f820208b09d2f38855498423e87dc5cdf4?environmentId=100
- https://www.reverse.it/sample/832c61741933c3a2de0ec5a28b195d8746d6d99b92f68f335252edba586d40c3?environmentId=100
- https://www.reverse.it/sample/c2c9a4e9079688476d2be31923108badda962e60ea41823f4d988d7f87088bb1?environmentId=100
- https://www.reverse.it/sample/e3f99995ae99190e1d363155db88e9645a0d2fd6484ec51e7834b224f1ebad31?environmentId=100
- https://www.reverse.it/sample/ad2f0a3eb16089c7c142808b07a2f5ee168747f1ee719804ea342f432bf501d8?environmentId=100
- C2:
- 95.85.19.195:80/data/info.php
- 188.127.249.32:80/data/info.php
- (dutluhnnx.info) 69.195.129.70:80/data/info.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement