Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-22 #locky email phishing campaign "Delivery #D-xxxxxxx"
- Email:
- ---------------------------------------------------------------------------------------------------------
- From: "Tina Burke" <Burke.63839@aaacoaching.com>
- To: [REDACTED]
- Subject: Delivery #D-8637942
- Date: Thu, 22 Sep 2016 14:52:15 -0300
- Dear [REDACTED], thank you very much for your order!
- Total amount of $768.75 was charged for your order #D-8637942.
- All the details are in the attachment. Delivery will arrive at 15:00 coming Monday.
- Attachment: eaf8ab5b0307.zip
- ---------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Delivery #D-<7 numbers>"
- - attached file "<random hexa chars>.zip" contains two files, one-letter-name junk file and "delivery details scan <random hexa>.js", a JScript downloader
- Download sites:
- http://abdrent.com/jg35c
- http://allbabyadvice-blog.com/u6hugrq
- http://americanjuniorgolfschool.com/45cl97uw
- http://aquobodge.com/06ndxl3
- http://aquobodge.com/37kc9
- http://artoccasions.com/e18ls
- http://aurylmorga.net/1jtjyz7q
- http://aurylmorga.net/4499sf
- http://bernardchandran.com/yt77q
- http://bircanogankul.com/dukfz
- http://bobneal.net/y7ynfwc
- http://bushidotactical.com/wojj7u1
- http://clempurry.net/2v9r9d
- http://clempurry.net/5du88
- http://couplestherapyexercises.com/qdjdm0o
- http://cyber-minipc.com/h8avxk
- http://drsearscoach.com/aa2iae
- http://hellolanguage.com/yk4qht82
- http://holidayhops.com/b87nop
- http://hotelcelnice.cz/vqjvduh
- http://hullpotterypriceguide.com/ifs2v4
- http://ipda.com.ua/37kc9
- http://kwmassage.com/b8cjbk
- http://lesiyteco.com/1774s4
- http://lesiyteco.com/3fgggff
- http://onmunrebut.com/24hydk
- http://onmunrebut.com/45cl97uw
- http://ooomaksim.ru/y431px
- http://signumtte.net/dkt4ln7
- http://sjunne.net/rzxh3
- http://sorrentovalleypainrelief.com/1774s4
- http://spkenig.ru/pyvr2io
- http://sportbkk.com/ifqia
- http://studioitaliacostruzioni.com/4499sf
- http://svityaz.net/utf8yn
- http://taladcaraudio.com/shl9lzvq
- http://tgr161.ru/h6mr0
- http://thcr.com/y2cfph
- http://thealchemyofjoy.com/ukfxxr4e
- http://theweekwines.com/yo1c40
- http://thisedu.com/t87wg07
- http://tuberro.com/f4gw67u
- http://u-flats.com/rfscc
- http://uv-print.ru/vmxdzp
- http://version-restaurant.com/80zivvz1
- http://zgqz11315.com/rt7vl
- Malware:
- - encoded on download
- ea723dfb99951fef1a5bd2c1d6a289b592c50a36deb58a5b4dc9bf6bf7291430 http___americanjuniorgolfschool.com_45cl97uw
- 060a0df4ec4e9e077f6ce76b39f63d7b6eb7863c110d31bd2e8ce9113800469d http___aquobodge.com_06ndxl3 [2]
- 2daf243d83d780455f534721111c9cb182fd677c3d40c3efd446274695ad8f89 http___aquobodge.com_37kc9
- b04d1ce71b89860e4e294f5733c9a081273e7ee6d5f6781c08988b901e5791d2 http___artoccasions.com_e18ls
- 72ba0618cccfcd472d75a28947d9d27e71467104246784de1e5e415ae7c021ab http___aurylmorga.net_1jtjyz7q [1]
- 945ab9a83ca05e15c13b8e5fe5af431254eae781c0f9fe7c86946bdecef1fa01 http___aurylmorga.net_4499sf
- 087c396b894059121821486a435366db2a1aeba0af4445085bf056ca0d6ba4fa http___bernardchandran.com_yt77q [4]
- 48b2bfe2afd35c5163f31549cef446ca3b9d75ede4d0f4b96e66368cfc747b4d http___bircanogankul.com_dukfz
- 1ab477d39013955da038cede09045b146a4c2725ea84df349131d3ba0c554d4b http___bushidotactical.com_wojj7u1
- d3f2ad5889c49643f3e9469aa332df49c8a9dc4f0b1d3b83bda647d3536991dc http___clempurry.net_2v9r9dc [3]
- fe46ddc0213ce62cc49c96a5a92b2552a93c350dc39c0d7d381e8e6c2c390f50 http___clempurry.net_5du88 [5]
- 15eeb68bb190ec3b752fd83748f79c689042619617d02cab401e5167a8bf9f5a http___cyber-minipc.com_h8avxk
- a6c308be741852fd87fba87d5cc8f7c05a0b1b1f851697c089f03b66851c0efc http___hellolanguage.com_yk4qht82
- 6b68b07c3bafe4e7883031e6eeeadc13bc2d053f275fdca1eccf3084d781568b http___holidayhops.com_b87nop
- 28a5f00f18d91298039918e3ed1d78e9892268b402f38ebd0e73d2bc5903e62e http___hotelcelnice.cz_vqjvduh
- 2cafc25f385bef78aa3675e5468758b4f1e46cabc0ae6da4680b607ab317491b http___hullpotterypriceguide.com_ifs2v4
- 2daf243d83d780455f534721111c9cb182fd677c3d40c3efd446274695ad8f89 http___ipda.com.ua_37kc9
- 05fc882b3411ee69f66dcf8a4a51e5712bc6dcab79bdc279705e7e10dffc6f22 http___kwmassage.com_b8cjbk
- a2fcb13fcd56ff76b410d0ef46b17dbc9d5cfd217178e872dd0a0141e0c7e57f http___lesiyteco.com_1774s4
- 9d01484fc8692a8173e800f3c7eb14752076266b8b7700fb760682cc4b8e41ac http___lesiyteco.com_3fgggff
- 1fb9f339b6cb21473d5a87889b5f145902315e16307bd38ec5ce624104b3fc2b http___onmunrebut.com_24hydk
- ea723dfb99951fef1a5bd2c1d6a289b592c50a36deb58a5b4dc9bf6bf7291430 http___onmunrebut.com_45cl97uw
- 4f81cf405f7be12865c482fc5a9be3a88f0bb959a677437583db1d6fa368e8fc http___ooomaksim.ru_y431px
- 218213f3b110e8dbdba03a08675614f91514538e55bb2f1dfbfba9709363ef32 http___signumtte.net_dkt4ln7
- 1436ce7bd45f0cfa9957b341576acffa201dbcc1285bfcd9f25a840ff219a3ff http___sjunne.net_rzxh3
- a2fcb13fcd56ff76b410d0ef46b17dbc9d5cfd217178e872dd0a0141e0c7e57f http___sorrentovalleypainrelief.com_1774s4
- 6214591eb1ae8f6f4831d90adf8a0d71689778218b36b14778bab51989b7f602 http___spkenig.ru_pyvr2io
- 6c158e3be12d56f649c4e2d64c35d7edf26d432d66cb67c565bc8d820a781822 http___sportbkk.com_ifqia
- 70fdbb271be5ab134d5521162d6752f3d775fb5bff346799408e3d1e7563c71e http___svityaz.net_utf8yn
- 1a4ab9bca62f2bbf32135bdbacaa87a9258adc477aa591a637db355b7f55855e http___taladcaraudio.com_shl9lzvq
- dbd5aea98fb14995d2505255b1c43c9fa3a53542b85cc1b0358e1d208a96ccac http___tgr161.ru_h6mr0
- 7ebeee77f3bd790f32c9187dce52f1fa60d7bf579b13d1e133fec11f9984cbe8 http___thcr.com_y2cfph
- 011b5c5d14e9b2bc15875256bfb5d711d228ebc82fc388ba41697dee5db82e81 http___thealchemyofjoy.com_ukfxxr4e
- e6c8928885d7b28f76af110a3f65d2c816887bfd14eed32c90c3a10a5a6d5c78 http___theweekwines.com_yo1c40
- cdd87561a16cc3fa42a09d0dcfa7c02976f3afa36dd73296d3627dfd2b1e611d http___thisedu.com_t87wg07
- 760f250424eec0ef45fe8a7a0fc1ff276a150b01efc09d4463c68a1f515ac18e http___u-flats.com_rfscc
- 993cb96076fad2f4465e864ef7405be6877eaed1950cf8e33ebf49cc524e1cb4 http___uv-print.ru_vmxdzp
- b9c846b3b99d8fc10038ddb9fb9b539c4b7d23e60d6e7dc38290487b163fd0e3 http___version-restaurant.com_80zivvz1
- 45ab4780772b34ff609cc39abbbfac366ec5e0fc3d901eb1ecc8f81cd20224f5 http___zgqz11315.com_rt7vl
- - decoded
- 4199faf58975dcb1416edf073db54682b42a52bc0de21f761d68b20b6628a4c7 [1]
- 39af06ae5bf746caea0fdfaf7b7009323029146a2cf5541cbdc9cc946b0d67ed [2]
- 9efed491c46abd9d3a0a2ba9ff29f6fdc717233b4e09cfa9089267795f3ead6d [3]
- a0be3e12ad794a7949d44b71d6025588873737b68d80778f2e5f191484a6413f [4]
- c618dfa8f9e819b943450546b85621a4036f419db53f23c0a026242b17f81881 [5]
- - executed by "rundll32.exe %TEMP%\<ddl_name>,qwerty 323"
- - samples
- https://www.reverse.it/sample/908ac1eeade10f9df494b890ff066539b5f892ea752278839da0c0b0bf540945?environmentId=100
- https://www.reverse.it/sample/89943599c8193015b87201112e29d816856885b90573adc6058111ac395c5c2c?environmentId=100
- https://www.reverse.it/sample/ef6e6bf2688d0c7ad97f98de4629f84eaf57d2864eb6493403247c2c6ab7f210?environmentId=100
- https://www.reverse.it/sample/d4febb21e207652bbd26aa9deb9ffffdfbfdde1e361cd7cdd772db43c6558b02?environmentId=100
- https://www.reverse.it/sample/db16f930bc80845a23f1abf9b9122bd1de20e9239d94231aa4c3a21507021527?environmentId=100
- https://www.reverse.it/sample/3df89e9b85ce1d95fee1380f12455cb2a598f3f0e8c5493e444dc7e3f24899fd?environmentId=100
- C2:
- 51.254.108.40:80/data/info.php
- 94.242.57.152:80/data/info.php
- tswsgajtwhqkosd.su/data/info.php [91.239.235.130]
- wnrgttsfmhfmmoqxm.biz/data/info.php [69.195.129.70]
- jfmiondv.xyz/data/info.php [91.239.235.130]
Add Comment
Please, Sign In to add comment