Racco42

2017-10-04 Locky "Copy of invoice ANNNNNNNNNN"

Oct 4th, 2017
5,054
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.06 KB | None | 0 0
  1. 2017-10-04: #locky email phishing campaign "Copy of invoice ANNNNNNNNNN. Please find your invoice attached."
  2.  
  3. Email sample:
  4. -----------------------------------------------------------------------------------------------------------------
  5. To: [REDACTED]
  6. Subject: Copy of invoice A3229365915. Please find your invoice attached.
  7. Date: Wed, 04 Oct 2017 14:38:16 +0530
  8.  
  9. Dear customer
  10.  
  11. Thank you for shopping with Electricfix. A copy of your invoice is
  12. attached. If your invoice is not attached please email
  13.  
  14. Order number: A3229365915
  15.  
  16. Forward planning:
  17. While we try our hardest to get your products to you in time and in
  18. perfect condition, we suggest that you don’t schedule any
  19. installation work until a few days after the expected delivery date,
  20. just in case you need to resolve any technical questions or order
  21. additional fittings if necessary.
  22.  
  23. Disclaimer:
  24. This e-mail and any attachments are confidential. If you are not the
  25. intended recipient, please contact us immediately on 03330 112 333
  26. (mobile friendly) and inform the sender. Please then delete the e-mail
  27. and do not disclose the contents to anyone.
  28.  
  29. Although we do scan outgoing e-mails for viruses, it is possible that
  30. a virus may have become attached and it is your responsibility to scan
  31. incoming e-mails.
  32.  
  33. Contact Us:
  34. Telephone: 03330 112 333 (mobile friendly) UK based contact centre
  35. Address: Screwfix Direct Ltd, Trade House, Mead Avenue, Yeovil, BA22
  36. 8RT
  37. Company Registration No 03006378 VAT No 232 5555 75
  38.  
  39. Attachment: InvoiceA3229365915.7z -> Invoice415336724312713286955666.vbs
  40. -----------------------------------------------------------------------------------------------------------------
  41. - sender is "[email protected]"
  42. - subject is "Copy of invoice A<10 digits>. Please find your invoice attached."
  43. - attached file "InvoiceA<10 digits>.7z" contains file "Invoice<24 digits>.vbs", a VBScript downloader which will download malware from:
  44.  
  45. Download sites:
  46. http://cutwell.ca/8etyfh3ni
  47. http://derainlay.info/p66/8etyfh3ni
  48. http://ericweb.co.za/8etyfh3ni
  49. http://pciholog.ru/8etyfh3ni
  50. http://proteinmarker.com/8etyfh3ni
  51. http://rentwestq.com/8etyfh3ni
  52. http://schoensigns.com/8etyfh3ni
  53. http://scouting-bvb.nl/8etyfh3ni
  54. http://shopsshops.de/8etyfh3ni
  55. http://smarterbaby.com/8etyfh3ni
  56. http://spazioireos.it/8etyfh3ni
  57. http://tailer.it/8etyfh3ni
  58. http://tarimsalteknoloji.com/8etyfh3ni
  59. http://techknowlogix.net/8etyfh3ni
  60. http://tecnigrafite.com/8etyfh3ni
  61. http://turfschiploge.nl/8etyfh3ni
  62.  
  63. Updated:
  64. http://hwayou.com.tw/8etyfh3ni
  65. http://rocknsoulamerica.com/8etyfh3ni
  66. http://securmailbox.it/8etyfh3ni
  67.  
  68. Malware:
  69. - Locky ransomware, offlien ykcol version
  70. - SHA256: 7c88ec63f7ca11a22add9f77f47f7ac8f71e930b3dd24422940c28cc8fd22ac2, MD5: 3ba59430e3a75cf5c6ec1b7fcc5dfe33
  71. - VT: https://www.virustotal.com/file/7c88ec63f7ca11a22add9f77f47f7ac8f71e930b3dd24422940c28cc8fd22ac2/analysis/1507108536/
  72. - HA: https://www.reverse.it/sample/7c88ec63f7ca11a22add9f77f47f7ac8f71e930b3dd24422940c28cc8fd22ac2?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment