Advertisement
malwageddon

HSBC themed phishing

Jul 15th, 2013
424
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.00 KB | None | 0 0
  1. NOTE: Information is based on a sample of HSBC themed phishing email seen on 2013-07-15
  2.  
  3. -------------------------------------------------------------------
  4. From: "HSBC.co.uk" <service@hsbc.co.uk>
  5. Subject: Unable to process your most recent Payment
  6. Attachment: "HSBC_Payment_07152013.zip"
  7.  
  8. Body:
  9. You have a new e-Message from HSBC.co.uk. This e-mail has been sent to you to inform you that we were unable to process your most recent payment.Please check attached file for more detailed information on this transaction.Pay To Account Number: **********10 Due Date: 10/07/2013 Amount Due: $ 597.66 IMPORTANT: The actual delivery date may vary from the Delivery by date estimate. Please make sure that there are sufficient available funds in your account to cover your payment beginning a few days before Delivery By date estimate and keep such funds available until the payment is deducted from your account. If we fail to process a payment in accordance with your properly completed instructions, we will reimburse you any late-payment-related fees.
  10.  
  11. Copyright HSBC 2013. All rights reserved. No endorsement or approval of any third parties or their advice, opinions, information, products or services is expressed or implied by any information on this Site or by any hyperlinks to or from any third party websites or pages. Your use of this website is subject to the terms and conditions governing it. Please read these terms and conditions before using the website..
  12. -------------------------------------------------------------------
  13.  
  14. MD5s
  15. ZIP: dded1fe4a26b542f67c06da50445321f
  16. EXE: a467baa1cf081ce1d9f2d163a4677594 - https://www.virustotal.com/en/file/467bb750ac5c40c2ef430025c12ace53e7a5792dcf6d2afba9cac166e830ee44/analysis/
  17.  
  18. GETs:
  19. liltommy.com/ep9C.exe
  20. video.wmd-brokerchannel.de/qAz575t.exe
  21. www.oh-onlinehelp.com/Pefyi.exe
  22. www.wineoutleteventspace.com/7UNFVh.exe
  23.  
  24. POSTs:
  25. alabamaenergysuppliers.com/ponyb/gate.php
  26. arizonaenergysuppliers.com/ponyb/gate.php
  27. dharmaking.net/ponyb/gate.php
  28. dharmaking.org/ponyb/gate.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement