Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-16 #locky email phishing campaign "IMG, FAX, DOC, SCAN"
- Email:
- -----------------------------------------------------------------------------------------------------------------
- From: "Winifred" <Winifred1@[REDACTED]>
- To: [REDACTED]
- Subject: FAX_3450
- Date: Fri, 16 Sep 2016 15:37:04 +0530
- Attachment: FAX_3450.zip
- -----------------------------------------------------------------------------------------------------------------
- - sender address is random, but seems to belong to same domain as recipient
- - body is empty
- - subject has format [FAX|DOC|SCAN|IMG]_<4 digit number>
- - attachment <%subject%>.zip contains file <random chars>.wsf a JScript downloader
- Download sites (actual URLs conain suffix ?<random>=<random> which does not influence download):
- http://1express.com.sg/54JHbjgcDLG
- http://24hourprintshop.com/54JHbjgcDLG
- http://46709394.com/54JHbjgcDLG
- http://adityastar.com/54JHbjgcDLG
- http://all4supply.com/54JHbjgcDLG
- http://anythingsteel.com/54JHbjgcDLG
- http://apro88.com/54JHbjgcDLG
- http://barcelona4fun.com/54JHbjgcDLG
- http://b-creative.be/54JHbjgcDLG
- http://bsm.sk/54JHbjgcDLG
- http://chelsea-west.com/54JHbjgcDLG
- http://criar-meu-site.com/54JHbjgcDLG
- http://curlysol.com/54JHbjgcDLG
- http://dailymandi.com/54JHbjgcDLG
- http://demo.website.pl/54JHbjgcDLG
- http://earnbyemail.com/54JHbjgcDLG
- http://fgspro.com/54JHbjgcDLG
- http://gizlot.com/54JHbjgcDLG
- http://helpmybathroom.com/54JHbjgcDLG
- http://honeydavis.us/54JHbjgcDLG
- http://incarmo.ru/54JHbjgcDLG
- http://inovsol.com/54JHbjgcDLG
- http://islamiccollege.org/54JHbjgcDLG
- http://jsydjc.com/54JHbjgcDLG
- http://kolben.cz/54JHbjgcDLG
- http://kwiry.com/54JHbjgcDLG
- http://mahovik-bg.com/54JHbjgcDLG
- http://markanltd.com/54JHbjgcDLG
- http://mfcomputer.net/54JHbjgcDLG
- http://miamilimosina.com/54JHbjgcDLG
- http://mudelts.com/54JHbjgcDLG
- http://mytourbid.com/54JHbjgcDLG
- http://nipeldogalgaz.com/54JHbjgcDLG
- http://paraspokeri.net/54JHbjgcDLG
- http://psychquiz.com/54JHbjgcDLG
- http://qarmoo.com/54JHbjgcDLG
- http://rentvspb.ru/54JHbjgcDLG
- http://salemwitchcat.com/54JHbjgcDLG
- http://samenart.com/54JHbjgcDLG
- http://sanalnet.org/54JHbjgcDLG
- http://sds-india.org/54JHbjgcDLG
- http://shopmjn.com/54JHbjgcDLG
- http://sinergica.cl/54JHbjgcDLG
- http://sstaswim.com/54JHbjgcDLG
- http://swivelsrus.com/54JHbjgcDLG
- http://timnhadat.com/54JHbjgcDLG
- http://tobybender.com/54JHbjgcDLG
- http://travelvoice.com/54JHbjgcDLG
- http://wordpresshosting.co.il/54JHbjgcDLG
- http://xn--41a.xn----8sbivjiocsggj.xn--p1ai/54JHbjgcDLG
- http://xsolution.sk/54JHbjgcDLG
- Malware
- - encoded on download, SHA256 528455065a7c975bfaa3674f6a1dcf051fd69cba4ba81321f7d32269fb99a5bb, filesize 155648 bytes
- - decoded SHA256 1d0148fc0bd53b9ed5837b827543a93e280812d13d5a34d9b83d2527b61dfaed
- - execution: "rundll32.exe %TEMP%\<name>.dll,qwerty"
- https://www.reverse.it/sample/3f0c23957f1c0ebcfae7be2dca6a6a4105bcc463167e75575edbfd6444ef2dcb?environmentId=100
- https://www.reverse.it/sample/d7bdef77ff55b6492450e049784d07cc7aa06deda45db8c9c4db4f8f7dd4d032?environmentId=100
- https://www.reverse.it/sample/c2a6412fbf57a7a4e1f3984915f3874f3e0cc4a9749f634f7de6c00688393cbe?environmentId=100
- https://www.reverse.it/sample/c1ca393ec9cc9ae747ddec82e73aaf2703449b3a2f1644dbb978369f063ee0ac?environmentId=100
- C2:
- - no C2 communication visible
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement