Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-08-09: #Locky email phishing camapign "E 2017-08-09 (xxx).doc"
- Samples: 1334
- Email sample:
- --------------------------------------------------------------------------------------------------------------
- From: Jeanne@[REDACTED]
- To: [REDACTED]
- Subject: E 2017-08-09 (87).xls
- Date: Mon, 24 Jul 2017 07:51:08 +0000
- Attachment: "E 2017-08-09 (87).zip" -> "E 2017-08-09 (443).vbs"
- --------------------------------------------------------------------------------------------------------------
- - sender address is faked to look to be from same domain as recepient
- - subject is "E 2017-08-09 (<2-3 digits>).<doc|docx|xls|xlsx|jpg|tiff|pdf|jpg>"
- - email body is empty
- - attached file "E 2017-08-09 (<2-3 digits>).zip" contains file "E 2017-08-09 (<2-3 digits>).vbs" a VBScript downloader
- Download sites:
- http://3sat.fr/y872ff2f
- http://adnangul.av.tr/y872ff2f
- http://aedelavenir.com/y872ff2f
- http://aisp74.asso.fr/y872ff2f
- http://ambrogiauto.com/y872ff2f
- http://apositive.be/y872ff2f
- http://atesbocegianaokulu.com/y872ff2f
- http://attilabalogh.com/y872ff2f
- http://autoecole-jeanpierre.com/y872ff2f
- http://auto-ecole-lecastelet.com/y872ff2f
- http://auxilia-fr.com/y872ff2f
- http://azlinshaharbi.com/y872ff2f
- http://bayimpex.be/y872ff2f
- http://beansviolins.com/y872ff2f
- http://binarycousins.com/y872ff2f
- http://boschettoristorante.it/y872ff2f
- http://busad.com/y872ff2f
- http://camefe.com.mx/y872ff2f
- http://campusvoltaire.com/y872ff2f
- http://cipemiliaromagna.cateterismo.it/y872ff2f
- http://dbr663dnbssfrodison.net/af/y872ff2f
- http://fachwerkhaus.ws/y872ff2f
- http://flooringforyou.co.uk/y872ff2f
- http://greenerlivingca.com/y872ff2f
- http://henweekendsbirmingham.co.uk/y872ff2f
- http://homeownersinsurance.ca/y872ff2f
- http://iida-sevensuns.com/y872ff2f
- http://jaysonmorrison.com/y872ff2f
- http://llallagua.ch/y872ff2f
- http://melting-potes.com/y872ff2f
- http://peluqueriacaninaencordoba.com/y872ff2f
- http://saunaesofmansatis.net/y872ff2f
- http://searchlightcare.com/y872ff2f
- http://tasgetiren.com/y872ff2f
- http://telesolutionsconsultants.com/y872ff2f
- http://themeastralgratuit.com/y872ff2f
- http://willemshoeck.nl/y872ff2f
- Malware:
- - SHA256: 390ed1dde4ff03adfcf67c59ee02567ac5665bb5e029eaebf0332bc81e4d1891, MD5: 0d0823d9a5d000b80e27090754f59ee5
- - VT: https://www.virustotal.com/file/390ed1dde4ff03adfcf67c59ee02567ac5665bb5e029eaebf0332bc81e4d1891/analysis/1502275376/
- - HA: https://www.reverse.it/sample/390ed1dde4ff03adfcf67c59ee02567ac5665bb5e029eaebf0332bc81e4d1891?environmentId=100
- - C2:
- POST http://83.217.8.61/checkupdate
- POST http://31.202.130.9/checkupdate
- POST http://91.234.35.106/checkupdate
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement