Racco42

2017-07-25 TrickBot "< No Subject >"

Jul 25th, 2017
3,638
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.18 KB | None | 0 0
  1. 2017-07-25 #trickBot email phishing campaign "< No Subject >"
  2. Samples: 458
  3.  
  4. Email sample:
  5. -----------------------------------------------------------------------------------------------------------------------
  6. To: [REDACTED]
  7. Subject: < No Subject >
  8. Date: Wed, 26 Jul 2017 01:57:26 +0300
  9.  
  10. Good Day,
  11.  
  12. Please see attached email bill request from May-July 2017.
  13.  
  14. Yours Sincerely,
  15. Sandy
  16. D354810
  17.  
  18. Attachment: May-July2017.zip
  19. -----------------------------------------------------------------------------------------------------------------------
  20. - sender is "[email protected]"
  21. - subject is "< No Subject >"
  22. - attached file "May-July2017.zip" contains file "<3 upcase letters>_ <11 digits>_<6 digits>.wsf", a which when executed will downaload 2nd stage downloader from:
  23.  
  24. Stage2 download sites:
  25. http://acomplia.orgfree.com/8?
  26. http://delicefilm.com/cgi-bin/10?
  27. http://dodawanie.com/1?
  28. http://esu-tech-saar.de/4?
  29. http://gala.noads.biz/2?
  30. http://huairou.com/3?
  31. http://kpalion.piwko.pl/12?
  32. http://mavisehirrotaract.org/cgi-bin/5?
  33. http://naturis.info/6?
  34.  
  35. Stage2 downloader is a MSHTA file containing VBScript downloader which will download malware from:
  36.  
  37. Malware download sites:
  38. http://1pointsix18.in/n3f7b
  39. http://eselink.com.my/n3f7b
  40. http://gotchawildlife.com/n3f7b
  41. http://infopoupees.com/n3f7b
  42. http://olsonlamaj.com/n3f7b
  43. http://potsdamer-strassenfest.de/n3f7b
  44. http://rencontre-rouen.com/n3f7b
  45. http://sakrabeskydy.wz.cz/n3f7b
  46. http://starsafety.net/n3f7b
  47. http://sunbrio.com/n3f7b
  48. http://thelaw.ae/n3f7b
  49. http://trominguatedrop.org/af/n3f7b
  50. http://wirbeldipf.ch/n3f7b
  51.  
  52. Malware:
  53. - encoded on download SHA256 932cc394f05ae536e98b9861bfc854251023809ae8099f2cb6af16c28f6300bd, MD5 e0aee94076700e1bcb6b9eac6121a9bb
  54. - decode by XORing with "ur43vUVcQMub86bdFOwgt1rZJjssOXNj"
  55. - decoded SHA256 b7a7d715f370142ddc6d1ba15f9f7377cda3995d4726874d4eeda24d4b9eff13, MD5 90284b01fae8a932ca99767825568721
  56. - VT: https://www.virustotal.com/file/b7a7d715f370142ddc6d1ba15f9f7377cda3995d4726874d4eeda24d4b9eff13/analysis/1501024947/
  57. - HA: https://www.reverse.it/sample/b7a7d715f370142ddc6d1ba15f9f7377cda3995d4726874d4eeda24d4b9eff13?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment