Advertisement
Racco42

2016-12-20 Locky "for printing"

Dec 20th, 2016
2,879
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.77 KB | None | 0 0
  1. 2016-12-20: #locky email phishing campaign "for printing"
  2.  
  3. Email sample:
  4. ------------------------------------------------------------------------------------------------------------------
  5. From: TAMMY MALTMAN <[email protected]>
  6. To: [REDACTED]
  7. Date: Tue, 20 Dec 2016 16:15:08 +0530
  8. Subject: for printing
  9.  
  10. Hi,
  11.  
  12. For printing.
  13. Thank you so much.
  14. --
  15.  
  16. *TAMMY MALTMAN CristobalHRD/Admin Officer*
  17. *Moonbake Inc.14 Langka St., Golden Acres Talon 1*
  18. *Las Pi=C3=B1as City, Philippines 1630Tel. No.: 632 8004373, 632 8022645Telefax:
  19. 632 8022645*
  20.  
  21. *Mobile Number: +63932-845-9007Email Address: [email protected]
  22.  
  23. Attachment: Certificate_60447.xls
  24. ------------------------------------------------------------------------------------------------------------------
  25. - sender varies between emails
  26. - subject is "for printing"
  27. - attached file "Certificate_<4-8 digits>.xls" is a Microsft Excel 2007+ file containing macro that will download malware:
  28.  
  29. Download sites:
  30. http://artlab.co.il/hjv56
  31. http://avenueresto.com/hjv56
  32. http://bluelunar.net/hjv56
  33. http://charlenelouw.co.za/hjv56
  34. http://devzendo.org/hjv56
  35. http://eagleslearning.com/hjv56
  36. http://farbybialystok.pl/hjv56
  37. http://forstmog.de/hjv56
  38. http://fsamson.com/hjv56
  39. http://guide4health.info/hjv56
  40. http://hostalmilabi.com/hjv56
  41. http://householdanimals.50webs.com/hjv56
  42. http://imperialroofing.co.uk/hjv56
  43. http://inzt.net/hjv56
  44. http://ipt.se/hjv56
  45. http://jaba-translations.pt/hjv56
  46. http://jansen.com.ua/hjv56
  47. http://jayacoat-industries.com.my/hjv56
  48. http://kakamiao.com/hjv56
  49. http://kmwine.ge/hjv56
  50. http://kodivac.com/hjv56
  51. http://kungfumasterwang.com/hjv56
  52. http://ldagnes.pl/hjv56
  53. http://minilab.ca/hjv56
  54. http://mk-beauty.de/hjv56
  55. http://nanomedilac.com/hjv56
  56. http://nfia-china.com/hjv56
  57. http://no1archeryandsports.ca/hjv56
  58. http://owncloud.weber-rechtenbach.de/hjv56
  59. http://paplanindustries.com/hjv56
  60. http://pozsgaiingatlan.hu/hjv56
  61. http://residencegardenia.it/hjv56
  62. http://shouxinghg.com/hjv56
  63. http://stav-reporter.ru/hjv56
  64. http://tc12345.com/hjv56
  65. http://theservantsoflove.com/hjv56
  66. http://todoalojamiento.es/hjv56
  67. http://www.genesisbilling.net/hjv56
  68. http://www.grupoaex.es/hjv56
  69. http://www.inglesenveranoenjavea.com/hjv56
  70. http://www.junaida.com/hjv56
  71.  
  72. UPDATE:
  73. http://ashpeptide.com/hjv56
  74. http://cracoviamanor.com/hjv56
  75. http://ingemanns-autolakering.dk/hjv56
  76. http://klimatshop.sk/hjv56
  77. http://phayamengrai.chiangrai.doae.go.th/hjv56
  78. http://stuifmeelenstamper.be/hjv56
  79. http://webplatter.com/hjv56
  80. http://www.rencontreparis.org/hjv56
  81. http://www.tenji-guide.com/hjv56
  82.  
  83. UPDATE:
  84. http://adminca.se/hjv56
  85. http://alaliengineering.net/hjv56
  86. http://isriir.com/hjv56
  87. http://jimprudom.com/hjv56
  88. http://noosnegah.com/hjv56
  89. http://revolutionarymom.com/hjv56
  90. http://tanz-trommeln.at/hjv56
  91. http://www.judo-hattingen.de/hjv56
  92. http://yorkshire-pm.com/hjv56
  93.  
  94. UPDATE:
  95. http://carloszubiaga.com/hjv56
  96. http://corlouis.com/hjv56
  97. http://gages-56.com/hjv56
  98. http://kayju.com/hjv56
  99. http://knightsure.co.uk/hjv56
  100. http://macoinservicios.com/hjv56
  101. http://namecardcenter.net/hjv56
  102. http://www.azrodandclassic.com/hjv56
  103. http://www.langeoog-meerleben.de/hjv56
  104.  
  105. Malware:
  106. - encoded on download, SHA256 3e813c9aef93c3ee00c89f99ee3e67314417b3d492c175a0633c0bb61cd03bef, MD5 20bac7aa46a9d2f0f19e54ed36a9b0fd
  107. - decoded SHA256 3f474165756cfb12f459379420447e397e966fc4b665c1ec90d894772926f893, MD5 c46d07a05d498cf4178d3092ee62aa07
  108. - executed by "rundll32.exe %TEMP%\<filename>.vip,vape"
  109. - sample: https://www.virustotal.com/file/3f474165756cfb12f459379420447e397e966fc4b665c1ec90d894772926f893/analysis/1482233488/
  110.  
  111. C2:
  112. POST http://176.121.14.95/checkupdate
  113. POST http://188.127.239.48/checkupdate
  114. POST http://193.201.225.124/checkupdate
  115. POST http://91.203.5.144/checkupdate
  116. POST http://91.223.180.3/checkupdate
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement