Advertisement
Antelox

New Locky distribution sites - 23/06/2016 continue

Jun 23rd, 2016
278
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. *Email sample*
  2.  
  3. _Subject_: Payment
  4.  
  5. _Body_:
  6.  
  7. Dear [NAME],
  8.  
  9. Our records show that we have not yet received payment for the previous order #A-532173
  10. Could you please send payment as soon as possible?
  11.  
  12. Please find attached file for details.
  13.  
  14.  
  15. Yours sincerely
  16. Jeremy Jackson
  17. Operations Director (CEO Designate)
  18.  
  19.  
  20. In attachment a zip archive with a javascript file.
  21.  
  22. Javascript sample - MD5: b217ece3ecf33fd6fc624af5d25f0840
  23. VT: 1/56 - https://www.virustotal.com/en/file/a7e93e059bf53885110dddb52b5029e4e5c0b35f98ab3981a26b80a47118905d/analysis/
  24.  
  25. *Compromised domains (47)*:
  26.  
  27. 98.131.20.17/ o41d3
  28. bbmarilu.it/ f7x1378
  29. bbvogliadimare.it/ h573kdg
  30. bolanoid.ru/ vjqraq
  31. btgnj.com/ a6308b
  32. caseificiodesantis.it/ bmvl5xz
  33. centrosportivoiunco.it/ c42en
  34. cm-seia.pt/ 0q6d4ej
  35. cond.gribochechki.ru/ zibni
  36. control-seduction.private.pl/ eu5c1q
  37. darts-pr.ru/ 6m5hl
  38. deangelis.co.uk/ 9189x
  39. dice-design.com/ 9cotr5w
  40. dugganinternational.ca/ jlv43q0
  41. edilperle.it/ b354kx0o
  42. fastmoneyloan.info/ 0h1vsa63
  43. fitnesclub.ru/ oc7xhbuc
  44. folkchata.pl/ wmm4i0
  45. follyfoot.org/ todl3fc
  46. garnelenfarm.net/ jixh4iz
  47. genius-versand.de/ 9kme7u
  48. hate-metal.com/ hre8fqo
  49. hoosiernetwork.com/ 6oa4xhk
  50. hotstreams.ru/ o1cri71
  51. hudebiah.net/ uhpdylx4
  52. ilbalconcino2011.it/ bzukq
  53. ingstroymash.ru/ m92xv
  54. itc.slav.dn.ua/ w4b7m0
  55. karl-lee.se/ x23ft
  56. marchandedidees.fr/ o1236qw
  57. maydenehotelblackpool.com/ 4qjb81gs
  58. modband.com/ a4jw2if
  59. mr2peter.de/ myu3a6ge
  60. namifitnessclub.it/ c6y9dcms
  61. newgeneration2010.it/ cx6uxxg5
  62. newpark.co.uk/ 54yp9
  63. oavb.com/ 9hh3ybox
  64. potolok-profit.ru/ od0xz9xv
  65. redpower.com.au/ xlkdld
  66. saintkatherine.orthodoxy.ru/ 5uj4u6
  67. staffsolut.nichost.ru/ qimiiud
  68. turniejkrzyz.za.pl/ fz0i11
  69. uas-aas.ca/ 4bwbk5
  70. usdavetrana.it/ c474o
  71. vonenidan.de/ kdwytr
  72. www.johnlodgearchitects.com/ fx89v
  73. www.puertasjoaquin.com/ nl5tl
  74.  
  75. *Sampled downloaded and decoded*:
  76.  
  77. File Name: fksdOKooVkA.exe
  78. MD5: 8137DC850A9F2593F331A149D6CC17CF
  79. VT 13/54 - https://virustotal.com/en/file/6f292ac37fb327ce7223f4e7d58b93f0f3038f279ac54348c2cef430aacc44d8/analysis/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement