Advertisement
DarthInvader

March 7 2018 Emotet indicators of phishing

Mar 7th, 2018
831
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.33 KB | None | 0 0
  1. March 7 2018 Emotet indicators of phishing
  2. Some of these sites came in late March 6 2018
  3.  
  4. From addresses
  5.  
  6. Subject
  7. New order
  8. Document needed
  9. Invoice
  10. Outstanding Invoices
  11. Invoice receipt
  12. Open Past Due Orders
  13. Paid Invoice
  14. Past Due Invoice
  15.  
  16. No payload http://www.se-beach-karting.at/Overdue-payment/
  17. No payload http://www.cultravel.it/Invoice-Number-01350/
  18. No payload http://стоматология-на-алексеева.рф/Service-Invoice
  19. No payload http://rebus-metod.net/2-Past-Due-Invoices/
  20. No payload http://автогазсервис34.рф/Summit-Companies-Invoice-483821/
  21. No payload http://educational.academy/Sales-Invoice/
  22.  
  23. Unverified URLs
  24. http://khabarovskstroy27.ru/Past-Due-Invoice/
  25. http://spastikengellilerfederasyonu.com/Important-Please-Read/
  26. http://agrologsa.com/XGT4x/
  27. http://restaurantemexicanofrida.com/Paid-Invoices/
  28. http://website1.italix.info/wp-content/UPS-Express-Domestic/Mar-06-18-08-48-54/
  29.  
  30. The sites below serve the same payload file, just different file names
  31. https://www.virustotal.com/en/file/11837a032823b811d66754917b7ae99ec2315ea5b7bfd659a2c16625e94bd099/analysis/1520435368/
  32. https://www.hybrid-analysis.com/sample/11837a032823b811d66754917b7ae99ec2315ea5b7bfd659a2c16625e94bd099?environmentId=100
  33.  
  34. Site Active file:Invoices attached.doc
  35. http://kil-more.net/Open-Past-Due-Orders/
  36.  
  37. Site Active file:Past Due Invoices.doc
  38. http://web-courses.com.au/Invoices-Overdue/
  39.  
  40. Site Active file:Paid Invoices.doc
  41. http://strawberryfields.info/Invoice-Corrections-for-82746759/
  42.  
  43. Site Active file:Paid Invoice & Credit Card Receipt.doc
  44. http://kil-more.net/Open-Past-Due-Orders/
  45.  
  46. Site Active file:Outstanding Invoices.doc
  47. http://rkn-it.net/Invoice-for-you/
  48.  
  49. Site Active file:Outstanding Invoices.doc
  50. http://www.stocksport-natternbach.at/Service-Report-64203/
  51.  
  52. The sites below have a different payload than the sites above
  53. https://www.virustotal.com/en/file/9ff75bc185bcb9f01cac41dd0679cd260fea02b9145c95230e2c08c3f8bc3452/analysis/1520444572/
  54. Site Active File:Service Invoice.doc
  55. http://gustavorique.com.br/Invoice-for-f/l-03/07/2018/
  56.  
  57. Site ACtive File:Service Invoice.doc
  58. http://anuradhaseneviratna.com/Outstanding-Invoices/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement