Racco42

2017-09-20 Locky "Status of invoice A217xxx"

Sep 20th, 2017
4,068
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.96 KB | None | 0 0
  1. 2017-09-20: email phishing campaign "Status of invoice A217NNNN-NN"
  2.  
  3. Email sample:
  4. ---------------------------------------------------------------------------------------------------------------
  5. From: "Marta Scrivens" <[email protected]>
  6. To: [REDACTED]
  7. Subject: Status of invoice A2172208-39
  8. Date: Wed, 20 Sep 2017 11:19:03 +0300
  9.  
  10. Hello,
  11.  
  12. Could you please let me know the status of the attached invoice? I
  13. appreciate your help!
  14.  
  15. Best regards,
  16.  
  17. Marta Scrivens
  18. Tel: 206-575-6675 x 100
  19. Fax: 206-575-8533
  20.  
  21. Attachment: A2172208-39.rar -> 20080920_333407.vbs
  22. ---------------------------------------------------------------------------------------------------------------
  23. - attached file "A217<4 digits>-<2 digits>.rar" contains file "20080920_<6 digits>.vbs", a VBScript downloader
  24.  
  25. Download sites:
  26. http://68.171.49.151/RSkfsNR7
  27. http://digiviews.co.uk/RSkfsNR7
  28. http://hard-grooves.com/RSkfsNR7
  29. http://hellonwheelsthemovie.com/RSkfsNR7
  30. http://mariamandrioli.com/RSkfsNR7
  31. http://pyefittedfurniture.co.uk/RSkfsNR7
  32. http://rockrak.com/RSkfsNR7
  33. http://ryterorrephat.info/af/RSkfsNR7
  34. http://viwa.homelinux.com/RSkfsNR7
  35. http://wilvreeburg.nl/RSkfsNR7
  36.  
  37. Malware:
  38. - locky, offline .yclok variant
  39. - SHA256: da386efced7535a1262ae9ede6988e27bdc6fca3411da14e6db02158aa37a5c9, MD5: fd365e280b5d5125d7045fd10f877e58
  40. - SHA256: 614bfea6b81f56b59bd0f2222b65b57571796245a7886a8e31be8a3ccd0e5617, MD5: 051abecc907d95bac508bb5445bd55eb
  41. - VT: https://www.virustotal.com/en/file/da386efced7535a1262ae9ede6988e27bdc6fca3411da14e6db02158aa37a5c9/analysis/1505895881/
  42. - VT: https://www.virustotal.com/#/file/614bfea6b81f56b59bd0f2222b65b57571796245a7886a8e31be8a3ccd0e5617/detection
  43. - HA: https://www.reverse.it/sample/da386efced7535a1262ae9ede6988e27bdc6fca3411da14e6db02158aa37a5c9?environmentId=100
  44. - HA: https://www.reverse.it/sample/614bfea6b81f56b59bd0f2222b65b57571796245a7886a8e31be8a3ccd0e5617?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment