malware_traffic

2020-05-04 (Monday) - malspam with XLS file pushing Dridex

May 4th, 2020
1,589
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2020-05-04 (MONDAY) - MALSPAM WITH XLS ATTACHMENTS PUSHING DRIDEX
  2.  
  3. RELATED TO:
  4.  
  5. - https://twitter.com/reecdeep/status/1257311243796271104
  6.  
  7. DATA FROM 10 EMAIL EXAMPLES:
  8.  
  9. EXAMPLE OF SENDING MAIL SERVERS:
  10.  
  11. - Received: from ([37.176.91.105])
  12. - Received: from ([78.134.7.212])
  13. - Received: from 84.120.142.211.dyn.user.ono.com ([84.120.142.211])
  14. - Received: from 93-46-193-98.ip109.fastwebnet.it ([93.46.193.98])
  15. - Received: from ([93.151.233.33])
  16. - Received: from ([177.184.221.68])
  17. - Received: from ([179.24.74.84])
  18. - Received: from ([188.114.75.201])
  19. - Received: from ([195.210.41.158])
  20. - Received: from ([197.20.95.235])
  21.  
  22. SENDER EMAIL ADDRESS:
  23.  
  24. - From: "\Intuit E-Commerce Service\" <quickbooks@notification.intuit.com>
  25.  
  26. SUBJECT LINE EXAMPLES:
  27.  
  28. - Subject: April Inv # 357104
  29. - Subject: April Inv # 555930
  30. - Subject: April Inv # 963620
  31. - Subject: Invoice 837535
  32. - Subject: Invoice 848137
  33. - Subject: Invoice/Sales Receipt 432499
  34. - Subject: Invoice/Sales Receipt 689708
  35. - Subject: Purchase Order/Invoice 852029
  36. - Subject: Reminder: Invoice 180460
  37. - Subject: Reminder: Invoice 217567
  38.  
  39. ATTACHMENT NAME EXAMPLES:
  40.  
  41. - Attachment name: invoice_357104.xls
  42. - Attachment name: invoice_555930.xls
  43. - Attachment name: invoice_837535.xls
  44. - Attachment name: Invoice_180460_.xls
  45. - Attachment name: Invoice_217567_.xls
  46. - Attachment name: Invoice_432499_.xls
  47. - Attachment name: Invoice_689708_.xls
  48. - Attachment name: Invoice_848137_.xls
  49. - Attachment name: Invoice_852029_.xls
  50. - Attachment name: Invoice_963620_.xls
  51.  
  52. EXAMPLES OF ATTACHMENTS:
  53.  
  54. - SHA256 hash: 19042ea0e61783a3c281e3f02e0e2e2b07e9421bae0afeeae21febe450510f0c
  55. - File size: 64,000 bytes
  56. - File name: Invoice_050706_.xls
  57.  
  58. - SHA256 hash: 5cf7bc9a59fcd10c02ca84c8dc4993b6f4425c645d863e69ea146668acf244a4
  59. - File size: 64,002 bytes
  60. - File name: invoice_984162.xls
RAW Paste Data