Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-08 #locky email phishing campaign "Your Amazon order has dispatched"
- - the downloaders, URLs and malware are the same as for "Fax transmission" campign http://pastebin.com/Uzmft3Lp
- Email sample:
- ---------------------------------------------------------------------------------------------------
- From: "Amazon Inc" <auto-shipping21@amazon.com>
- To: [REDACTED]
- Subject: [SUSPICIOUS MESSAGE] Your Amazon.com order has dispatched (#927-6424906-7525554)
- Date: Tue, 8 Nov 2016 23:57:54 +0100 (CET)
- Dear Customer,
- Greetings from Amazon.com,
- We are writing to let you know that the following item has been sent using Royal Mail.
- For more information about delivery estimates and any open orders, please visit: http://www.amazon.com/your-account
- Your order #927-6424906-7525554 (received November 8, 2016)
- Your right to cancel:
- At Amazon.com we want you to be delighted every time you shop with us. O=3D
- ccasionally though, we know you may want to return items. Read more about o=3D
- ur Returns Policy at: http://www.amazon.com/returns-policy/
- Further, under the United Kingdom's Distance Selling Regulations, you have =3D
- the right to cancel the contract for the purchase of any of these items wit=3D
- hin a period of 7 working days, beginning with the day after the day on whi=3D
- ch the item is delivered. This applies to all of our products. However, we =3D
- regret that we cannot accept cancellations of contracts for the purchase of=3D
- video, DVD, audio, video games and software products where the item has be=3D
- en unsealed. Please note that we are unable to accept cancellation of, or r=3D
- eturns for, digital items once downloading has commenced. Otherwise, we can=3D
- accept returns of complete product, which is unused and in an "as new" con=3D
- dition.
- Our Returns Support Centre will guide you through our Returns Policy and, w=3D
- here relevant, provide you with a printable personalised return label. Ple=3D
- ase go to http://www.amazon.com/returns-support to use our Returns Suppor=3D
- t Centre.
- To cancel this contract, please pack the relevant item securely, attach you=3D
- r personalised return label and send it to us with the delivery slip so tha=3D
- t we receive it within 7 working days after the day of the date that the it=3D
- em was delivered to you or, in the case of large items delivered by our spe=3D
- cialist couriers, contact Amazon.com customer services using the link bel=3D
- ow within 7 working days after the date that the item was delivered to you =3D
- to discuss the return.
- https://www.amazon.com/gp/css/returns/homepage.html
- For your protection, where you are returning an item to us, we recommend th=3D
- at you use a recorded-delivery service. Please note that you will be respon=3D
- sible for the costs of returning the goods to us unless we delivered the it=3D
- em to you in error or the item is faulty. If we do not receive the item bac=3D
- k from you, we may arrange for collection of the item from your residence a=3D
- t your cost. You should be aware that, once we begin the delivery process, =3D
- you will not be able to cancel any contract you have with us for services c=3D
- arried out by us (e.g. gift wrapping).
- Please also note that you will be responsible for the costs of collection i=3D
- n the event that our specialist courier service collect a large item from y=3D
- ou to return to us.
- As soon as we receive notice of your cancellation of this order, we will re=3D
- fund the relevant part of the purchase price for that item.=3D20
- Should you have any questions, feel free to visit our online Help Desk at:=3D
- =3D20
- http://www.amazon.com/help
- If you've explored the above links but still need to get in touch with us, =3D
- you will find more contact details at the online Help Desk.=3D20
- Note: this e-mail was sent from a notification-only e-mail address that can=3D
- not accept incoming e-mail. Please do not reply to this message.=3D20
- Thank you for shopping at Amazon.com
- -------------------------------------------------
- Amazon EU S.=3DC3=3DA0.r.L.
- c/o Marston Gate
- Ridgmont, BEDFORD MK43 0XP
- United Kingdom
- -------------------------------------------------
- Attachment: ORDER-927-6424906-7525554.zip
- ---------------------------------------------------------------------------------------------------
- - sender is "Amazon Inc" or "Amazon.com", autoshipping<digits>@amazon.com
- - subject is "Your Amazon.com order has dispatched (#<3 digits>-<7 digits>-<7 digits>)"
- - attached file "ORDER-<3 digits>-<7 digits>-<7 digits>.zip" contain file "F-<10 digits>-<10 digits>-201611<6 digits>-<4 digits>.js", a JScript downloader
- Download sites (actual URLs have ?<random>=<random> which does not influence the download):
- http://chewysissy.net/7845gf
- http://gadgetdealz.net/7845gf
- http://heatsavingsystems.com/7845gf
- http://helpcomm.com/7845gf
- http://hnzhengzhou.com/7845gf
- http://hud3.net/7845gf
- http://hunt-magazine.com/7845gf
- http://hz9m.com/7845gf
- http://immobilienbegleitung.de/7845gf
- http://i-solutions.cz/7845gf
- http://ivocal.fr/7845gf
- http://jgtour.wz.cz/7845gf
- http://jlxzy.net/7845gf
- http://jrockish.bravepages.com/7845gf
- http://karacanalbum.com/7845gf
- http://kleansys.com/7845gf
- http://kolumbia.free.bg/7845gf
- http://kurdinfo.ru/7845gf
- http://markscheffel.de/7845gf
- http://masterimob.ro/7845gf
- http://matemshkola.ru/7845gf
- http://mavicicek.com/7845gf
- http://meshok.com.ua/7845gf
- http://mokinukai.lt/7845gf
- http://monkey-drum.com/7845gf
- http://musicrecruiting.com/7845gf
- http://myhtar.ru/7845gf
- http://myxos.be/7845gf
- http://teazexebec.com/7845gf
- Malware:
- - encoded on download SHA256 b5164a2f4ea1c7a2d338f47b7b391cfda6f8be6a7a2e3e3d9fc070dda863fdc5, MD5 d2888f6c40e32714a65f23df32a6930d
- - decoded SHA256 57a0f81246a70462028c1adf1b5d8f02580845084e12a5edf3652bb2d9b2077d, MD5 ad6fb318002df4ffc80795cc31d529b4
- - executed by "rundll32.exe %Temp%\<dll_name>,nipple"
- C2:
- POST http://85.143.212.23/message.php
- POST http://158.69.223.5/message.php
- POST http://qyxrdhfuufn.biz/message.php
- POST http://npgmteapwbncfch.xyz/message.php
- POST http://gfytvimwwi.pl/message.php
- POST http://xuotcothbuhat.pw/message.php
- POST http://lanubxgujiclwvbvw.work/message.php
- POST http://xuotcothbuhat.pw/message.php
- POST http://rktjbvxjbihrqdlvh.info/message.php
- POST http://xuotcothbuhat.pw/message.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement