Racco42

2017-09-04 GlobeImposter "True Telecom Invoice"

Sep 4th, 2017
4,420
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.57 KB | None | 0 0
  1. 2017-09-04 #globeimposter email phishing campaign "True Telecom Invoice"
  2.  
  3. Email sample:
  4. -----------------------------------------------------------------------------------------------------------------------
  5. To: [REDACTED]
  6. Subject: 59922362 - True Telecom Invoice for August 2017
  7. Date: Mon, 04 Sep 2017 17:46:39 +0430
  8.  
  9. Dear Deborah Day
  10.  
  11. We have attached your latest True Telecom bill for August 2017.
  12. View your bill online
  13.  
  14. To be able to read your invoice file you will require the Adobe Acrobat PDF viewer. You August already have this installed,
  15. if not please visit the Adobe website and download their free viewer.
  16.  
  17. Payments made by direct debit will be collected 14 days from the date of the Bill.
  18.  
  19. If you wish to contact us, please do not hesitate to get in touch with one of our friendly customer services agents.
  20.  
  21. Telephone: 0800 840 40 60
  22. Fax: 0844 779 2253
  23.  
  24. Please be advised that this is an unmonitored email address.
  25.  
  26. With Kind Regards,
  27.  
  28. The True Telecom Team
  29. www.True-Telecom.com
  30.  
  31.  
  32. True Telecom Ltd is registered in England and Wales No. 08225783.
  33. Head Office address: Ground Floor,Lakeview West, Galleon Boulevard, Crossways Business Park, Dartford, Kent, DA2 6QE
  34.  
  35. This communication together with any attachments transmitted with it ("this E-Mail") is intended only for the use of the addressee and August contain information which is privileged and confidential. If the reader of this E-Mail is not the intended recipient or the employee or agent responsible for delivering it to the intended recipient you are hereby notified that any use, dissemination, forwarding, printing or copying of this E-Mail is strictly prohibited. Addressees should check this E-mail for viruses. The Company makes no representations as regards the absence of viruses in this E-Mail. If you have received this E-Mail in error please immediately delete, erase or otherwise destroy this E-Mail and any copies of it. Any opinions expressed in this E-Mail are those of the author and do not necessarily constitute the views of the Company. Nothing in this E-Mail shall bind the Company in any contract or obligation. The Company only guarantees service in accordance with the service charter. The company accepts no liability for failure of hardware after the termination point. For the purposes of this E-Mail "the Company" is the trading name of True Telecom Ltd. True Telecom Ltd (Registered in England & Wales No. 08225783)
  36.  
  37. Attachment: 2017-08-51237335-Bill.7z ->
  38. -----------------------------------------------------------------------------------------------------------------------
  39. - sender is [email protected]
  40. - subject is <8 digits> - True Telecom Invoice for August 2017
  41. - body is in HTML format and contains link to file with downloader which is same as the one in attachment
  42. - attached file "2017-08-<8 digits>-Bill.7z" contains file "2017-08-<8 digits>-Bill.vbs", a VBScript downloader which will download from:
  43.  
  44. Downloader download sites:
  45. http://aac-autoecole.com/2017-08-42007004-Bill.7z
  46. http://activ-conduite.eu/2017-08-42007004-Bill.7z
  47. http://autoecolecarnot.com/2017-08-42007004-Bill.7z
  48. http://montessibooks.com/2017-08-42007004-Bill.7z
  49. http://pack-lines.com/2017-08-42007004-Bill.7z
  50. http://red-dead.fr/2017-08-42007004-Bill.7z
  51. http://rogames.ro/2017-08-42007004-Bill.7z
  52. http://studiotoscanosrl.it/2017-08-42007004-Bill.7z
  53. http://toubelis.gr/2017-08-42007004-Bill.7z
  54. http://ventadepajaros.es/2017-08-42007004-Bill.7z
  55. http://villasbarcelona.org/2017-08-42007004-Bill.7z
  56. http://weekendjevliegen.nl/2017-08-42007004-Bill.7z
  57.  
  58. Malware download sites:
  59. http://aquavista.org.nz/JIKJHgft
  60. http://awholeblueworld.com/JIKJHgft
  61. http://cabbiemail.com/JIKJHgft
  62. http://geolearner.com/JIKJHgft
  63. http://handhi.com/JIKJHgft
  64. http://hexacam.com/JIKJHgft
  65. http://jimaylor.net/JIKJHgft
  66. http://m-tensou.net/JIKJHgft
  67. http://n1xua.com/JIKJHgft
  68. http://naturofind.org/p66/JIKJHgft
  69. http://proyectogambia.com/JIKJHgft
  70. http://world-tour2000.com/JIKJHgft
  71.  
  72. Malware:
  73. - encoded on download, SHA256: 4b1097886cde91d2c4d66fdb53e446d94e34d692fbbd2b5475a065c5c30a901e, MD5: 3134ff6529ef055b232452e3f29bdece
  74. - decode by XORing with "XdSk4gxRmVKXKBlRXHLa29VxIpIIegBH"
  75. - decoded SHA256: bb1df4a93fc27c54c78f84323e0ea7bb2b54469893150e3ea991826c81b56f47, MD5: 6b456cff688be4715e6456cf12c64939
  76. - VT: https://www.virustotal.com/en/file/bb1df4a93fc27c54c78f84323e0ea7bb2b54469893150e3ea991826c81b56f47/analysis/1504531635/
  77. - HA: https://www.reverse.it/sample/bb1df4a93fc27c54c78f84323e0ea7bb2b54469893150e3ea991826c81b56f47?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment