Ledger Nano X - The secure hardware wallet
SHARE
TWEET

2020-05-04 (Monday) - malspam with XLS file pushing Dridex

malware_traffic May 4th, 2020 (edited) 1,053 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2020-05-04 (MONDAY) - MALSPAM WITH XLS ATTACHMENTS PUSHING DRIDEX
  2.  
  3. RELATED TO:
  4.  
  5. - https://twitter.com/reecdeep/status/1257311243796271104
  6.  
  7. DATA FROM 10 EMAIL EXAMPLES:
  8.  
  9. EXAMPLE OF SENDING MAIL SERVERS:
  10.  
  11. - Received: from ([37.176.91.105])
  12. - Received: from ([78.134.7.212])
  13. - Received: from 84.120.142.211.dyn.user.ono.com ([84.120.142.211])
  14. - Received: from 93-46-193-98.ip109.fastwebnet.it ([93.46.193.98])
  15. - Received: from ([93.151.233.33])
  16. - Received: from ([177.184.221.68])
  17. - Received: from ([179.24.74.84])
  18. - Received: from ([188.114.75.201])
  19. - Received: from ([195.210.41.158])
  20. - Received: from ([197.20.95.235])
  21.  
  22. SENDER EMAIL ADDRESS:
  23.  
  24. - From: "\Intuit E-Commerce Service\" <quickbooks@notification.intuit.com>
  25.  
  26. SUBJECT LINE EXAMPLES:
  27.  
  28. - Subject: April Inv # 357104
  29. - Subject: April Inv # 555930
  30. - Subject: April Inv # 963620
  31. - Subject: Invoice 837535
  32. - Subject: Invoice 848137
  33. - Subject: Invoice/Sales Receipt 432499
  34. - Subject: Invoice/Sales Receipt 689708
  35. - Subject: Purchase Order/Invoice 852029
  36. - Subject: Reminder: Invoice 180460
  37. - Subject: Reminder: Invoice 217567
  38.  
  39. ATTACHMENT NAME EXAMPLES:
  40.  
  41. - Attachment name: invoice_357104.xls
  42. - Attachment name: invoice_555930.xls
  43. - Attachment name: invoice_837535.xls
  44. - Attachment name: Invoice_180460_.xls
  45. - Attachment name: Invoice_217567_.xls
  46. - Attachment name: Invoice_432499_.xls
  47. - Attachment name: Invoice_689708_.xls
  48. - Attachment name: Invoice_848137_.xls
  49. - Attachment name: Invoice_852029_.xls
  50. - Attachment name: Invoice_963620_.xls
  51.  
  52. EXAMPLES OF ATTACHMENTS:
  53.  
  54. - SHA256 hash: 19042ea0e61783a3c281e3f02e0e2e2b07e9421bae0afeeae21febe450510f0c
  55. - File size: 64,000 bytes
  56. - File name: Invoice_050706_.xls
  57.  
  58. - SHA256 hash: 5cf7bc9a59fcd10c02ca84c8dc4993b6f4425c645d863e69ea146668acf244a4
  59. - File size: 64,002 bytes
  60. - File name: invoice_984162.xls
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top