Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-15 #locky email phishing campaign "SCAN"
- Email:
- ------------------------------------------------------------------------------------------------
- From: "Vonda trench" <logistics@polvige.com>
- To: [REDACTED]
- Date: Thu, 15 Sep 2016 11:39:38 +0200
- Subject: SCAN
- _____
- Vonda trench
- Logistics Department
- ALGRAFIKA SH.P.K
- Tel : +355 4 23 52 506
- Fax: +355 4 23 73 211
- Mobile : +355 67 40 46 320
- Web : http://www.polvige.com
- Attachment: "SCAN_20160915_4058772597.zip"
- ------------------------------------------------------------------------------------------------
- - sender address varies, in format logistics@<domain>
- - subject is "SCAN"
- - Attachement "SCAN_20160915_<number>.zip" contains <random>.wsf with JScript downloader
- Download sites:
- http://bet4good.org/afdIJGY8766gyu
- http://bigfishcasting.com/afdIJGY8766gyu
- http://charlcote1.net/afdIJGY8766gyu
- http://delicefilm.com/afdIJGY8766gyu
- http://dendang.net/afdIJGY8766gyu
- http://eiti.co.il/afdIJGY8766gyu
- http://hawaiipoliticalinfo.org/afdIJGY8766gyu
- http://insideinsights.net/afdIJGY8766gyu
- http://insieutoc.com/afdIJGY8766gyu
- http://keratin.sk/afdIJGY8766gyu
- http://kf-design.com/afdIJGY8766gyu
- http://lacumpa.biz/afdIJGY8766gyu
- http://techboss.net/afdIJGY8766gyu
- http://tommylam.com/afdIJGY8766gyu
- UPDATE:
- http://espaciosamadhi.com/afdIJGY8766gyu
- http://fenwaycourier.com/afdIJGY8766gyu
- http://mika.tohmon.com/afdIJGY8766gyu
- http://oliveservicedapartments.com/afdIJGY8766gyu
- UPDATE2:
- http://allovercoupon.com/afdIJGY8766gyu
- http://americofernando.com/afdIJGY8766gyu
- http://credit-it.com/afdIJGY8766gyu
- http://electua.org/afdIJGY8766gyu
- http://lowcostveterinarios.com/afdIJGY8766gyu
- http://mumbomedia.nl/afdIJGY8766gyu
- http://pasbardejov.sk/afdIJGY8766gyu
- http://rimpro.ru/afdIJGY8766gyu
- http://salarypra1.net/afdIJGY8766gyu
- http://trudprom.ru/afdIJGY8766gyu
- http://zharikoff.ru/afdIJGY8766gyu
- UPDATE3:
- http://1natureresort.com/afdIJGY8766gyu
- http://discoverstillwater.com/afdIJGY8766gyu
- http://gearstuff.net/afdIJGY8766gyu
- http://iandistudio.com/afdIJGY8766gyu
- http://jxbestextile.com/afdIJGY8766gyu
- http://lullaby-babies.co.uk/afdIJGY8766gyu
- http://lusanmaster.com/afdIJGY8766gyu
- http://ocscexpo.net/afdIJGY8766gyu
- http://onefilmy.com/afdIJGY8766gyu
- http://sandpiperchorus.us/afdIJGY8766gyu
- http://sapanboon.com/afdIJGY8766gyu
- Malware:
- - encoded on download, SHA256 c9b7c221208a2d459503b836a1f9c727041170e139523db65dee487db74498e2, filesize 258560 bytes
- - decoded SHA256, f68a383f7f27a8ac1f1cc9040bcbb11747412d2193d6eaa508d010eef3d59d76, filesize 258560 bytes
- - executed by "rundll32.exe %TEMP%\YgXrvSpiw1.dll,qwerty"
- https://www.reverse.it/sample/d37af7fb2a2ca387b8d1febf4acdcdd9e45337773e3d3fccdd2571955ac52ebf?environmentId=100
- https://www.reverse.it/sample/7089ddb070e7902c1422075ee5bc7d8d7a59080867d6b6dc80d1dcdc63e4779f?environmentId=100
- https://www.reverse.it/sample/95f63a38b9fabd64357b485736f40469438fafffd5f438cfe09f5316715a7fbb?environmentId=100
- https://www.reverse.it/sample/20702e287e9483875460c39cc9f76fd7a9bae6516b138b92397ebe84e00e5b24?environmentId=100
- https://www.reverse.it/sample/a3851868bba572b8054fe64ce0354546b32e6cab74a608eb3030416ba27e2a56?environmentId=100
- C2:
- -no C2 connections
Add Comment
Please, Sign In to add comment