Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-09-21: #locky email phishing camapaign "Invoice RE-2017-09-21-NNNNN"
- Email sample:
- -----------------------------------------------------------------------------------------------------------------------------
- From: Amazon Marketplace <AOUXQckbAEkCV@marketplace.amazon.co.uk>
- To: [REDACTED]
- Subject: Invoice RE-2017-09-21-00168
- Date: Thu, 21 Sep 2017 12:16:52 +0430
- ------------- Begin message -------------
- Dear customer,
- We want to use this opportunity to first say "Thank you very much for your purchase!"
- Attached to this email you will find your invoice.
- Kindest of regards,
- your Amazon Marketplace
- [commMgrHmdToken:MDJSMKJWGJIJN]
- ------------- End message -------------
- For Your Information: To help arbitrate disputes and preserve trust and safety, we retain all messages buyers and sellers send through Amazon.co.uk. This includes your
- response to the message below. For your protection we recommend that you only communicate with buyers and sellers using this method.
- Important: Amazon.co.uk's A-to-z Guarantee only covers third-party purchases paid for through our Amazon Payments system via our Shopping Cart or 1-Click. Our Guarantee
- does not cover any payments that occur off Amazon.co.uk including wire transfers, money orders, cash, check, or off-site credit card transactions.
- We want you to buy with confidence whenever you purchase products on Amazon.co.uk. Learn more about Safe Online Shopping (http://www.amazon.co.uk/gp/help/customer/display.html?nodeId=11081621) and our safe buying guarantee (http://www.amazon.co.uk/gp/help/customer/display.html?nodeId=3149571).
- [commMgrTok:MDJSMKJWGJIJN]
- Attachment: RE-2017-09-21-00168.7z -> RE-2017-09-21-00297.vbs
- -----------------------------------------------------------------------------------------------------------------------------
- - sender is "Amazon Marketplace" <random>@marketplace.amazon.co.uk
- - subject is "Invoice RE-2017-09-21-<5 digits>"
- - attached file "RE-2017-09-21-<5 digits>.7z" contains file "RE-2017-09-21-<5 digits>.vbs", a VBScript downloader
- Download sites:
- http://81552.com/IUGiwe8
- http://accuflowfloors.com/IUGiwe8
- http://adr-werbetechnik.de/IUGiwe8
- http://aetozi.gr/IUGiwe8
- http://afmance.it/IUGiwe8
- http://afradem.com/IUGiwe8
- http://agricom.it/IUGiwe8
- http://agriturismobellaria.net/IUGiwe8
- http://agro-kerler.de/IUGiwe8
- http://ahlbrandt.eu/IUGiwe8
- http://fulcar.info/p66/IUGiwe8
- http://moonmusic.com.au/IUGiwe8
- Malware:
- - locky, offline .ykcol variant
- - VT: https://www.virustotal.com/en/file/ac6da4890150e2037a5913623557ab759b62d0ee9206ec0bacac318523afbc53/analysis/1505984851/
- - HA: https://www.hybrid-analysis.com/sample/ac6da4890150e2037a5913623557ab759b62d0ee9206ec0bacac318523afbc53?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement