Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-08-30 #locky email phishing campaign "987nkjh8" / "Document, Image, Photo, Photos, Picture"
- Email
- - sender address varies, but comes from same domain as recepient
- - subject can be one of - Document, Image, Photo, Photos, Picture
- - body of email is empty (just one = character)
- - attachment is as zip file "XX_20160830_AA_BB_CC_Pro.zip" (XX = DC, IG, PC, PH, WP)
- - inside a zipfile is a <random_chars>.wsf file containing JScript downloader
- Download sites (actual URLs have suffix of ?<random>=<random>, but it has no effect on downloaded data):
- http://alians-ekb.ru/987nkjh8
- http://aptosruralescasadelaabuela.es/987nkjh8
- http://arcziuuucity.y0.pl/987nkjh8
- http://chwiladlaciebie.cba.pl/987nkjh8
- http://cmacos.com/987nkjh8
- http://earthkikaku.web.fc2.com/987nkjh8
- http://gastrohurt.neostrada.pl/987nkjh8
- http://gerochan.web.fc2.com/987nkjh8
- http://lacomete52.perso.sfr.fr/987nkjh8
- http://marronbridge.ina-ka.com/987nkjh8
- http://muellerfalk.homepage.t-online.de/987nkjh8
- http://nihilismus.web.fc2.com/987nkjh8
- http://nishinomiyaseijunkai.web.fc2.com/987nkjh8
- http://og-kaiserslautern-kft.de/987nkjh8
- http://onlineportal-2012.de/987nkjh8
- http://rmpst.republika.pl/987nkjh8
- http://rs-nordsee.de/987nkjh8
- http://stanflorin10.go.ro/987nkjh8
- http://wolffram.homepage.t-online.de/987nkjh8
- http://www.artx.strefa.pl/987nkjh8
- http://www.auret.at/987nkjh8
- http://www.dapaluda.it/987nkjh8
- http://www.facturi.go.ro/987nkjh8
- http://www.hiederer.de/987nkjh8
- http://www.lindenkapelle.de/987nkjh8
- http://www.lnowak.tkdami.net/987nkjh8
- http://www.peritiassicurativi.org/987nkjh8
- http://www.roboticapc.com/987nkjh8
- http://www.sand-mechanic.ru/987nkjh8
- http://www.shanty-chor-neuengoers.de/987nkjh8
- http://www.vilastefania.go.ro/987nkjh8
- http://www.welt-weit.info/987nkjh8
- http://zubimendi.com/987nkjh8
- Malware encoded, SHA256 6e3e22e7b848c5034a9ea3dce086f2cdb7d038e083844f54193449e62b7e13c0, filesize 151552 bytes
- https://www.reverse.it/sample/6baf9d0ffc8b0b344ef27bda8ed11b9fb4df03eae9dca6d2d102472cd2a8327c?environmentId=100
- https://www.reverse.it/sample/ac6cd2254a5a154f5159bce915311d6db4e090709552600a2e714bea61d652e5?environmentId=100
- https://www.reverse.it/sample/d379523f1006ae288acb053fcbc5af74877ef6727fd10f1d0f6440fdb6a94f6f?environmentId=100
- https://www.reverse.it/sample/311c6f45435d9f3f730839aa89319dbdb663ca8d3b00a1a9077688784a4ce016?environmentId=100
- https://www.reverse.it/sample/333c5025abaca8435e7b5e72d8b39db4f8ebee9d8de38beee74fec64f1cefc72?environmentId=100
- https://www.reverse.it/sample/6982b27ae64fc7f26bf7a214ab185087b332cb251de9118ce0eb0184c1e99ebf?environmentId=100
- https://www.reverse.it/sample/58d4c607da7427ea3ec9a9174f01e086c09d69c42ce64ee0d5eb1bde1f7f164b?environmentId=100
- C2s:
- 95.85.19.195:80/data/info.php
- 188.127.249.32:80/data/info.php
Add Comment
Please, Sign In to add comment