Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- thanks @James_inthe_box & @thlnk3r for additional phishing URLs
- PHISHING URLs
- hxxp://itfest[.]narfu[.]ru/docs/524161/
- hxxp://pictureframinguae[.]com/Outstanding-INVOICE-FNC/092999/845/
- hxxp://www[.]officeblocks[.]com[.]au/Outstanding-Invoices/
- hxxps://blog[.]jenkins[.]one/Overdue-payment/
- hxxp://yellowgorgeous[.]com/Purchases-2017/
- hxxp://www[.]oliviacandco[.]com/Final-Account/
- hxxp://smartthinkvietnam[.]net/Final-Account/
- hxxp://pghpermanentmakeup[.]com/Invoices-Overdue/
- hxxp://hugogabriel[.]ca/LOJPI9-3598915002/
- hxxp://bakeola[.]com/INCORRECT-INVOICE/
- hxxp://buildingbay[.]ca/Outstanding-INVOICE-QINHZ/1951204/508/
- hxxp://arvlon-art[.]com/Invoice/
- hxxp://www.1tds[.]net/wp/wp-content/Order-Confirmation/
- hxxp://e-eltom[.]pl/Invoice-Number-771614
- MALDOC DOWNLOADED FROM PHISHING URLs
- MD5 eaef4b19068aee4c6b1b17d96ddffc44
- SHA1 8fb66dde86a0dd52343a720e1f8209cf6de98c53
- SHA256 e706b3a32f4c177f1a3536dbd480c639666381b8a68b59821488116c51374eee
- EMOTET PAYLOAD URLs FROM MALDOC POWERSHELL
- hxxp://www[.]epiphanyazingefoundation[.]org/43gg6Nb/
- hxxp://www[.]fazendavida[.]com/Rfss/
- hxxp://inmonegreira[.]com/I2xPv/
- hxxp://hillbody[.]com/f0O0mL/
- hxxp://www[.]zavierdesign[.]com/0mRP/
- EMOTET PAYLOAD
- MD5 94725c2932f10e95831e537055afea74
- SHA1 b63670cf721736ba105937c41d8e3447892ec828
- SHA256 6c5fa9b58d2e3bfaad7963129fb2958bdd3aef5f110b54bd815bb8bd8ea07215
- PHISHING URLs #2
- hxxp://www[.]professionalshop[.]in/Sales-Invoice/
- hxxp://bootleggers66[.]com/Invoice-23060672/
- hxxp://kidzudaan[.]com/PIBU5-8772437751/
- hxxp://sharlotka38[.]ru/Outstanding-INVOICE-VTQQ/806878/098/
- hxxp://stjudesmedicalcentre[.]co[.]ke/QAWVA3-9981045821/
- hxxp://t-zulu[.]us/INCORRECT-INVOICE/
- hxxp://nhadatdonaland[.]com/Invoice/
- MALDOC DOWNLOADED FROM PHISHING URLs #2
- MD5 0bca0cda3bdab716ee8012d4adb9f5b1
- SHA1 8e745725c47ae8f6d7da6f590b90b13c473d3e91
- SHA256 60e0369e217e01371007b14a4b89de3db688abf1e424219146a924059b373844
- EMOTET PAYLOAD URLs FROM MALDOC POWERSHELL #2
- hxxp://www[.]zavierdesign[.]com/0mRP/
- hxxp://www[.]mivaso[.]cl/slhd1dv/
- hxxp://www[.]automobile-bebra[.]de/xiIItW/
- hxxp://iitainternationalhouse[.]org/QGO0E/
- hxxp://fixxoo[.]in/public/PRLm709/
- EMOTET PAYLOAD #2
- MD5 03968c19d136ce6048c889c4f7cf2c7e
- SHA1 8079ab7949a6b8ade0c5e83fd2551f6328dc00d7
- SHA256 4a2425d47015c457e0fe3c5b58d725c4d0152c11c268028d0d2f353d61120d11
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement