Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-21 #locky email phishing campaign "Package"
- Email:
- --------------------------------------------------------------------------------------------------------
- From: "Connie Sutton" <Sutton.95517@pangeaneering.com>
- To: [REDACTED]
- Subject: Package
- Date: Wed, 21 Sep 2016 16:59:51 +0530
- Dear customer, we have sent your package today. Please have a look at the receipt attached.
- No return or refund will be available without the receipt.
- Tracking ID - [c1f980dd5ead5ce1e41863808d81af530a]
- Thank you.
- Attachment: ce5168a6369f.zip
- --------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Package"
- - attached file <random hexa chars>.zip contain two files:
- - one-letter named zero-filled junkfile
- - "package receipt doc ~<random hexa>~.js"- a JScript downloader
- Download sites (all hosted on 190.147.38.2, 95.173.164.205):
- http://ammalewth.com/nve8vv
- http://ammalewth.com/q5i9v
- http://ammalewth.com/xk7us
- http://kinghokey.net/extxe73
- http://kinghokey.net/q74x0
- http://kinghokey.net/v9o4y2n
- http://sardexcel.com/9nh3kp
- http://sardexcel.com/int0hx
- http://sardexcel.com/ze8gh1
- http://soordchut.com/96tf5
- http://soordchut.com/hl6no
- http://soordchut.com/uk8gl8
- http://toaenvy.net/1822i
- http://toaenvy.net/osk51vd
- http://toaenvy.net/ujvcc8l0
- Malware:
- - encoded on download, filesize 156676 and 157188 bytes
- 268d1ebe4d7ac555124064804e9bcff558626e994961f8ae4f6a57066ed74737 http___ammalewth.com_nve8vv
- 428cec90ade72cd72cb7feb8cf8582588d75bedf7058530cafa9efbe81b5449f http___ammalewth.com_q5i9v
- 7174acdbb75f2c8da90a36631570c15030f78ff68ce9f2c8ff175a73ad4a14bc http___ammalewth.com_xk7us
- 13f397ed6f2c58b028f5346184525862a35524568e932b0c6d487155aea638a7 http___kinghokey.net_extxe73
- 2f2a79b9cc34ae81ee150560ef70f2c1e6cfdeca9583288a81900da63f7cfdc5 http___kinghokey.net_q74x0
- 8ca2ea672e67bb5c64ebbde34834bc1f0332db6aed30e32ca85fcfc4ea54f10b http___kinghokey.net_v9o4y2n
- 5e71783d442e4d74a719bb6674efbe8aaf068da17eca999de8dae6455e7ed850 http___sardexcel.com_9nh3kp
- 5b47ae849c4ebd4fa647acdf7d2602e72bbd6d99ca0c9536aed83345829d4375 http___sardexcel.com_int0hx
- e33860fe2419987060414f3ed9f7407d7a755d25bb447b319b7b12978c54b359 http___sardexcel.com_ze8gh1
- 0191c49d4d3f63293ba965326f7e83d69f614fe04391a3bb6fed72a745ac6d97 http___soordchut.com_96tf5
- d952b00fa47f988aa695bd9b7e5fbbaacd48b5f482a9b2a8ca0d42c23bcbde32 http___soordchut.com_hl6no
- 3f06cbeb5c08a3efd792dc12e89418233d5c25416840a8c5486307fe9bf7604a http___soordchut.com_uk8gl8
- 838358f16334f78c86440e0f46c80cfdf615ced86d74be390a92d19b8dd4332a http___toaenvy.net_1822i
- 82158baab7d136a9dfdf37b5e12e97c6dcc5277df6ea310216b9acea31879069 http___toaenvy.net_osk51vd
- 0e91201041fa35c004dea68ff5f0b96b109827b2f396af71519a30e95eb667c8 http___toaenvy.net_ujvcc8l0
- - decoded
- 571b55080ce62cdfddf0611c5f183a46ddf04d729ac9d3bde1ae1b57eea188cd
- 769c9c52c8a4d3567e3021450b3e40dec3ebec82957371cf3893444b4c2f5d1b
- c920284da131ce871bd3e419d8d80435de3112233272e72e525c2c285efa19a9
- - executed by "rundll32.exe %TEMP%\<dll_name>,qwerty 323"
- https://www.reverse.it/sample/54a7451a184fd8afa3cac9d787d5f83abeb8fecd14d9f136cff135e9f0d849e0?environmentId=100
- https://www.reverse.it/sample/4a4141c2adab0ebca262f25d7f6a45b773b074628a9522401e8dfa28d4889ccb?environmentId=100
- https://www.reverse.it/sample/3ca0d09b7236301b91e284f8a272f69a9a1f3fa158b4e8986af400dec545acab?environmentId=100
- https://www.reverse.it/sample/960b4c3b10bb54428dc28efdb559a533d7fe3cb117049c83d2a02862d8ec99f0?environmentId=100
- C2:
- 91.195.12.173:80/data/info.php
- 109.248.59.80:80/data/info.php
- ixearhbmeqsoeck.biz:80/data/info.php [91.239.235.130]
- faprgrrgp.biz:80/data/info.php [69.195.129.70]
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement