Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-09-05 #locky email phishing camaign "87b3ff3rc"
- Email sample:
- - Subject is constructed as [Attached|Copy|Emailing|File]: [Blank|IMG|INV|Invoice|Photo|Picture|Receipt](number)
- - Email body is empty
- - Sender address is faked to look like from same domain as recipients
- Attached file "[Blank|IMG|INV|Invoice|Photo|Picture|Receipt](number).zip" (same as part of Subject) contains file <random>.wsf which contains JScript downloader
- Download sites:
- http://52433865.fn.freenet-hosting.de/87b3ff3rc
- http://amii.50webs.com/87b3ff3rc
- http://bbruo.edurm.ru/87b3ff3rc
- http://boxpate.de/87b3ff3rc
- http://deemc.homepage.t-online.de/87b3ff3rc
- http://foto.hasimehrou.cz/87b3ff3rc
- http://frumuseanudaniela.go.ro/87b3ff3rc
- http://gregor-weiss.business.t-online.de/87b3ff3rc
- http://jvelizg.vtrbandaancha.net/87b3ff3rc
- http://kakeekoda.web.fc2.com/87b3ff3rc
- http://lanjaron.es.mialias.net/87b3ff3rc
- http://lcc.vtrbandaancha.net/87b3ff3rc
- http://maxshoppppsr.biz/js/87b3ff3rc
- http://miyufortuneteller.web.fc2.com/87b3ff3rc
- http://mojejeze.republika.pl/87b3ff3rc
- http://monkeeey.web.fc2.com/87b3ff3rc
- http://quietvain.nobody.jp/87b3ff3rc
- http://rakutenka.tuzikaze.com/87b3ff3rc
- http://religiaspoko.republika.pl/87b3ff3rc
- http://roadstercrew-nw.homepage.t-online.de/87b3ff3rc
- http://seikeiradioclub.web.fc2.com/87b3ff3rc
- http://tensai.wallst.ru/87b3ff3rc
- http://treasure-force.com/87b3ff3rc
- http://tvcm.com.br/87b3ff3rc
- http://www.bals.nichost.ru/87b3ff3rc
- http://www.birthmark.go.ro/87b3ff3rc
- http://www.equipe4.net/87b3ff3rc
- http://www.fabriziolovino.com/87b3ff3rc
- http://www.greentechdesign.ca/87b3ff3rc
- http://www.madonnaceleste.com/87b3ff3rc
- http://www.masamaru.net/87b3ff3rc
- http://www.officinaomc.com/87b3ff3rc
- http://www.poli-mec.it/87b3ff3rc
- http://www.rossorelli.ru/87b3ff3rc
- http://www.trzynastkajg.republika.pl/87b3ff3rc
- http://www.yacht-market.eu/87b3ff3rc
- http://yggithuq.utawebhost.at/87b3ff3rc
- Malware
- - encoded on download SHA256 13966e6557682c39a071198b201be0afb89922d4d25db9cbdec15a9142a20b78, filesize 201,216 bytes
- - decoded SHA256 bfe580cf1f33ec1c456385fef84ba01ca40a4e81833a8519b5b9b71e967d6444
- - RSA key is part of configuration, no C2 communication https://twitter.com/0xtadavie/status/772796495280111616
- https://www.reverse.it/sample/5444b5e28905855ac149784d59461a67f3ab216c847a9e1ad59004076171571b?environmentId=100
- https://www.reverse.it/sample/89e9924ce9bb332e1707eb32fa09843b9ae0dea769595beaa5a1f88653f1ef04?environmentId=100
- https://www.reverse.it/sample/ad8c71e18bf407173d5e6a7e877301478bb8f6d12fe331ffbf5b583915845640?environmentId=100
- https://www.reverse.it/sample/942f7a76811042cf90859667a217e8b8d597bfdd63b762691a24ee9c17f27c5c?environmentId=100
- https://www.reverse.it/sample/b2738a8ae1cea39b5ab5b6535398d54a5606a8df44c0cd97204eb2dc092d0481?environmentId=100
Add Comment
Please, Sign In to add comment