SHARE
TWEET

2017-05-24 Jaff "IMG_xxxx.pdf"

Racco42 May 24th, 2017 (edited) 769 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2017-05-24: #jaff email phishing campaign "IMG_xxxx.pdf"
  2.  
  3. Download sites:
  4. http://abcenglishclub.com/FsMflooY
  5. http://b.cms-hosting.by/FsMflooY
  6. http://better57toiuydof.net/af/FsMflooY
  7. http://billiginurlaub.com/FsMflooY
  8. http://david-faber.de/FsMflooY
  9. http://digital-helpdesk.com/FsMflooY
  10. http://dogplay.co.kr/FsMflooY
  11. http://ecoeventlogistics.com/FsMflooY
  12. http://elateplaza.com/FsMflooY
  13. http://electron-trade.ru/FsMflooY
  14. http://hr991.com/FsMflooY
  15. http://jinyuxuan.de/FsMflooY
  16. http://khaosoklake.com/FsMflooY
  17. http://minnessotaswordfishh.com/af/FsMflooY
  18. http://olgasmile.ru/FsMflooY
  19. http://oliverkuo.com.au/FsMflooY
  20. http://pcflame.com.au/FsMflooY
  21. http://tabelaistanbul.net/FsMflooY
  22. http://tbhomeinspection.com/FsMflooY
  23. http://tdtuusula.com/FsMflooY
  24. http://uslugitransportowe-warszawa.pl/FsMflooY
  25. http://williams-fitness.com/FsMflooY
  26.  
  27. Malware:
  28. - encoded on download SHA256 aa8ec3a016b5f12a5974a0c46aba8a3c3c4e4b6753c0e58705e15a73d0a7c234, MD5 be60ac06c22159319bd757e0c35be957
  29. - decode by XORing the data with key 1pBtVh8rkqQb9luW406gBgOR2UHpDVGI
  30. - decoded SHA256 077b498d9cc163e1ff5547e1abd625b8655f0339cb5e79d64c2ded17abb9e425, MD5 c9c897215e6f805eaf03ad56afd6e331
  31. - sample https://www.virustotal.com/en/file/077b498d9cc163e1ff5547e1abd625b8655f0339cb5e79d64c2ded17abb9e425/analysis/1495620406/
  32.  
  33. C2:
  34. http://y887drossetorling.info/a5/
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top