Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-12 #locky email phishing campaign "Budget report"
- http://blog.dynamoo.com/2016/09/malware-spam-budget-report-leads-to.html
- Email
- ---------------------------------------------------------------------------------------------------------------
- From: "Shawna Roberson" <Roberson.00148@americandream-redding.com>
- To: [REDACTED]
- Subject: Budget report
- Date: Mon, 12 Sep 2016 19:45:57 +0530
- Hi [REDACTED],
- I have partially finished the last month's budget report you asked me to do. Please add miscellaneous expenses in the budget.
- With many thanks,
- Shawna Roberson
- Attachment: "e3ac9b9be19.zip"
- ---------------------------------------------------------------------------------------------------------------
- - sender address varies
- - subject is "Budget report"
- - attached file "<random hexa chars>.zip" contain two identical files "<8 hexa chars> Budget_report_xls.js" and "<8 hexa chars> Budget_report_xls - 1.js"
- Download sites:
- http://block2enable3.net/1o6bcxr2
- http://canonbest7.com/1v1wwia
- http://lookbookinghotels.ws/a9sgrrak
- http://one4four1.ws/h27opn0
- http://trybttr.ws/h71qizc
- Malware:
- - encoded on download, filesize 134783 bytes, SHA256s:
- f35af296203a8c09e133cd202e27514ba21f014cb91c7e38411cf70bf23aa9de http___block2enable3.net_1o6bcxr2
- 5502098946874b806da019d37eab755db36951a7a4cc64c113a169aa53df9cdb http___canonbest7.com_1v1wwia
- 98bacd8eaaa7fa02ac1e817a015cce85c791879e69b866cac13b20231082d11d http___lookbookinghotels.ws_a9sgrrak
- d5dde8ef4f97cbb4bccfcc1d9854536ed7335065a92ffdd3f36e421e6c963962 http___trybttr.ws_h71qizc
- https://www.reverse.it/sample/bca67e8372897765e6f4265c7d27d3c2ed373833a0c577328601f6986b5db0c4?environmentId=100
- https://www.reverse.it/sample/b732899b4a9a94f4341427dd18cdc069902e79fef946addb42526e0aa7ff48f6?environmentId=100
- https://www.reverse.it/sample/da74b00b01220cb38f2ffca226d81079630d9dc3012b9888f8efe0472288cb1b?environmentId=100
- - decoded SHA256
- ad26b56690a9e79012bbf54112f66e029f16093b4dd4d842ba1fdebad1a8e094
- a7c5d185235e8515e546d720e565a3efbc4e1b169852453726d5673dca0ed2d4
- C2:
- 185.154.15.150:80/data/info.php
- 91.214.71.101:80/data/info.php
- 46.173.214.95:80/data/info.php
- 95.85.29.208:80/data/info.php
- 51.255.105.2:80/data/info.php
- yofkhfskdyiqo.biz:80/data/info.php [69.195.129.70]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement