Racco42

Locky "jhBHTYl"

Aug 31st, 2016
1,550
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.67 KB | None | 0 0
  1. 2016-08-31 #locky email phishing campaign "jhBHTYl" / "Fax, Image, IMG, my photo, Photo, photos"
  2.  
  3. Email sample
  4. - email body is empty
  5. - sender varies from email to email, but its domain is faked to be the same as recepient's
  6. - subject is one of: Fax, Image, IMG, my photo, Photo, photos
  7. - attached file "IMG_31082016_[random number].zip" contains file "[random chars].wsf" containing JScript downloader
  8.  
  9. Donwload sites (actual URLs have suffix ?<random>=<random>, but it does not have influence on donwload):
  10. http://adarutono1.x.fc2.com/jhBHTYl
  11. http://amii.50webs.com/jhBHTYl
  12. http://boxpate.de/jhBHTYl
  13. http://deemc.homepage.t-online.de/jhBHTYl
  14. http://dev-kev.com/jhBHTYl
  15. http://foto.hasimehrou.cz/jhBHTYl
  16. http://frumuseanudaniela.go.ro/jhBHTYl
  17. http://gregor-weiss.business.t-online.de/jhBHTYl
  18. http://iftikharchaudhry.50webs.com/jhBHTYl
  19. http://jvelizg.vtrbandaancha.net/jhBHTYl
  20. http://kakeekoda.web.fc2.com/jhBHTYl
  21. http://lanjaron.es.mialias.net/jhBHTYl
  22. http://lcc.vtrbandaancha.net/jhBHTYl
  23. http://mojejeze.republika.pl/jhBHTYl
  24. http://monkeeey.web.fc2.com/jhBHTYl
  25. http://quietvain.nobody.jp/jhBHTYl
  26. http://rakutenka.tuzikaze.com/jhBHTYl
  27. http://religiaspoko.republika.pl/jhBHTYl
  28. http://roadstercrew-nw.homepage.t-online.de/jhBHTYl
  29. http://rozalist.ru/jhBHTYl
  30. http://seikeiradioclub.web.fc2.com/jhBHTYl
  31. http://tvcm.com.br/jhBHTYl
  32. http://www.bals.nichost.ru/jhBHTYl
  33. http://www.birthmark.go.ro/jhBHTYl
  34. http://www.equipe4.net/jhBHTYl
  35. http://www.fabriziolovino.com/jhBHTYl
  36. http://www.greentechdesign.ca/jhBHTYl
  37. http://www.handyschmiede24.de/jhBHTYl
  38. http://www.madonnaceleste.com/jhBHTYl
  39. http://www.masamaru.net/jhBHTYl
  40. http://www.officinaomc.com/jhBHTYl
  41. http://www.poli-mec.it/jhBHTYl
  42. http://www.rossorelli.ru/jhBHTYl
  43. http://www.trzynastkajg.republika.pl/jhBHTYl
  44. http://www.yacht-market.eu/jhBHTYl
  45.  
  46. Malware
  47. - encoded on download, SHA256 5b9d7be09884e65c9e9484fe87bd9511b1cdeb831063abff4e37df1dc14f393a, filesize 200704
  48. - decoded SHA256 9e814af0b41ef947c8822799d3bd37929c28c92d3562b8e4eda4cb2240986b98
  49.  
  50. https://www.reverse.it/sample/4c919e457d6e69c96bb2e037c24d678d78f9cf70c6f5b74030684e09a63cd46b?environmentId=100
  51. https://www.reverse.it/sample/f71e81ce76b31a56923acd30d8444eee0af01d542bf975cbce603a9dada50d09?environmentId=100
  52. https://www.reverse.it/sample/255a3ac8806a0d8aa0b93bcdc6e9a41aade144968a69eaff64aa3b1cfebe1179?environmentId=100
  53. https://www.reverse.it/sample/044510cf9b3c0ac7c60df3a8717ed9d0f150112168d97c1cdbe63839d49fbeed?environmentId=100
  54. https://www.reverse.it/sample/957e0f2284f022d967f775cf1022d58a1acea8ac89e40c8979afcee1285638a6?environmentId=100
  55.  
  56. C2:
  57. 188.127.249.32:80/data/info.php
  58. 95.85.19.195:80/data/info.php
  59. (cufrmjsomasgdciq.pw) 91.223.180.66:80/data/info.php
Add Comment
Please, Sign In to add comment