Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-02: #locky email phishing campaign "part N"
- Email sample:
- -----------------------------------------------------------------------------------------------------------------------
- From: TRICIA SURGESON <triciasurgeson@our-event.org>
- To: [REDACTED]
- Subject: part 4
- Date: Wed, 02 Nov 2016 17:42:54 +0700
- As promised
- TRICIA
- Attached: "OKUZMFD1274.zip"
- -----------------------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "part <digit>"
- - attached file "<random chars><random number>.zip" contains "<random chars><random number>.wsf", a JScript downloader
- Download sites (actual URLs countain suffix ?<random>=<random> which does not influence the download):
- http://365aiwu.net/43ftybb8
- http://421pfyy.com/43ftybb8
- http://adasulamasistemleri.com/43ftybb8
- http://aifgroup.jp/43ftybb8
- http://aircrew.co.in/43ftybb8
- http://alkfor.ru/43ftybb8
- http://allebanken.net/43ftybb8
- http://almaks-mr.ru/43ftybb8
- http://animals.org.il/43ftybb8
- http://anime-one.com/43ftybb8
- http://arnaudgranata.com/43ftybb8
- http://atart.cn/43ftybb8
- http://atforum.pl/43ftybb8
- http://autoabs.lt/43ftybb8
- http://automaler.ru/43ftybb8
- http://awaelschool.com/43ftybb8
- http://ayulduz.biz/43ftybb8
- http://baraonda.gr/43ftybb8
- http://basketballninja.com/43ftybb8
- http://bassguitartips.com/43ftybb8
- http://battleduck.ch/43ftybb8
- http://bdvdo.net/43ftybb8
- http://beautyexpress.com.au/43ftybb8
- http://bechsautomobiler.dk/43ftybb8
- http://bestprservices.com/43ftybb8
- http://bha-group.eu/43ftybb8
- http://bhatiarasayanudyog.in/43ftybb8
- http://birthdaystoday.net/43ftybb8
- http://bluehost.hu/43ftybb8
- http://bogaziciradyo.com/43ftybb8
- http://bst.tw/43ftybb8
- http://buhlmend.net/43ftybb8
- http://cabanaionela.ro/43ftybb8
- http://carmenortigosa.com/43ftybb8
- http://chandrphen.com/43ftybb8
- http://cheappaintball.net/43ftybb8
- http://christen-in-nuernberg.de/43ftybb8
- http://christmas-metal-meeting.de/43ftybb8
- http://city-charger.ru/43ftybb8
- http://classicnet.ir/43ftybb8
- http://club-impact.ro/43ftybb8
- http://coinobras.com/43ftybb8
- http://consardproiectare.ro/43ftybb8
- http://corinnenewton.ca/43ftybb8
- http://cyclingpromotion.com.au/43ftybb8
- http://cyprushealthservices.com/43ftybb8
- http://d2dlaundry.com/43ftybb8
- http://debki-klara.pl/43ftybb8
- http://deborahshallcross.com/43ftybb8
- http://decactus.cl/43ftybb8
- http://delanothayer.cl/43ftybb8
- http://dersiz.com/43ftybb8
- http://desertkingwaterproofing.com/43ftybb8
- http://diandiandx.com/43ftybb8
- http://drossell.com/43ftybb8
- http://dwcell.com/43ftybb8
- http://ejiavip.com/43ftybb8
- http://eldamennska.is/43ftybb8
- http://eskopb.com/43ftybb8
- http://eurotrading.com.ua/43ftybb8
- http://evogelbacher.de/43ftybb8
- http://fibrotek.com/43ftybb8
- http://filmsites.nl/43ftybb8
- http://gzycgj.com/43ftybb8
- http://irk.24abcd.ru/43ftybb8
- http://wonnapian.com/43ftybb8
- UPDATED:
- http://677spo.com/43ftybb8
- http://abrahams.ch/43ftybb8
- http://beamit.be/43ftybb8
- http://bvn.lt/43ftybb8
- http://casadalocacao.com/43ftybb8
- http://cheedellahousing.com/43ftybb8
- http://contserv.ro/43ftybb8
- http://cxsd.com.cn/43ftybb8
- http://ecomission.com.au/43ftybb8
- http://el-sklep.com/43ftybb8
- http://enkobud.dp.ua/43ftybb8
- http://erotes.gr/43ftybb8
- http://xiguacity.com/43ftybb8
- Malware:
- - encoded on download, SHA 256 3511f8eb38e9faa1f9ac6a654eb31bb3b612a1ec65b4f58da11c7832d42cf197, filesize 323584
- - decoded SHA256 610e1f5a9386b13cbaac217f05f8089270136ccab00922856fb992eb08a9d12f
- - executed by "rundll32 <dll_name>,test123"
- - sample https://www.virustotal.com/en/file/610e1f5a9386b13cbaac217f05f8089270136ccab00922856fb992eb08a9d12f/analysis/
- C2:
- http://194.28.87.26/linuxsucks.php
- http://194.1.239.152/linuxsucks.php
- http://51.255.107.20/linuxsucks.php
- http://gxfbwjvior.biz/linuxsucks.php
- http://wpdrmxkbnjpoidf.biz/linuxsucks.php
- http://juykbsopyu.pw/linuxsucks.php
- http://evhblsxym.org/linuxsucks.php
- http://evhblsxym.org/linuxsucks.php
- http://pvdhqmbqwxx.org/linuxsucks.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement