Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-23 #locky email phishing campaign "Please pay attention"
- Email sample:
- ----------------------------------------------------------------------------------------------------------------
- From: "Wallace Guzman" <Guzman.Wallace@hoop-ology.com>
- To: [REDACTED]
- Subject: Please Pay Attention
- Date: Wed, 23 Nov 2016 14:49:36 +0530
- Dear [REDACTED], we have received your payment but the amount was not full.
- Probably, this occurred due to taxes we take from the amount.
- All the details are in the attachment - please check it out.
- Attachment: lastpayment_[REDACTED].zip
- ----------------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Please pay attention"
- - attached file "lastpayment_<recipient name>.zip" contains file "<random uppercase letters and digits>.js", a JScript downloader
- Download sites:
- http://broncvita.com/5vy2q
- http://broncvita.com/dvdzv
- http://broncvita.com/g7fiwm
- http://broncvita.com/gy3defplbd
- http://gurlfanam.net/bzv4jz9er
- http://gurlfanam.net/d4g73
- http://gurlfanam.net/krwjx
- http://gurlfanam.net/uhcgkozekr
- http://jinxlaze.com/emch2nr6
- http://jinxlaze.com/rysuuttn
- http://jinxlaze.com/vr2ltm
- http://nhatnang.vn/he5m5tfvih
- http://nicehdwall.com/lobvc
- http://nielsredeker.nl/gmcoirnrm
- http://nightpeople.co.il/xklqq33nr
- http://noveda.nl/viknlp3
- http://novinnic.ir/liinyes
- http://obtenloya.com/iksivwr
- http://ondeviesurgut.myjino.ru/4edogu
- http://opakowania.info/ickljgo
- http://opennano.pl/ewf1xe3i
- http://ovacii.biz/eh7xryos
- http://ovofit.cz/tcaulm
- http://ozzu.de/wdxzw
- http://pearlgonzalez.com/b9wawhy
- http://pensionwoehler.de/9jjgk
- http://pesci.ro/jgves
- http://pineysprat.com/fquah44d
- http://pineysprat.com/jd3gfy
- http://pineysprat.com/zqdjx
- http://playdog.ro/ufbuscn
- http://playtres.com.ar/3aepw
- http://plus39italiandesign.com/rtyww0
- http://poloneo.com/55bgq
- http://praam.cz/iessl
- http://pregnancysquare.com/diu9ktmd
- http://printo.nl/uxzw0mspm
- http://publygoo.it/u1rcrvfojx
- http://pvlabs.com/kby84bm
- http://qdweierya.com/qtubp
- http://rabavolgy.hu/utmu1mc
- http://racersguide.com/ghsgpxzovg
- http://reklomastik.com/8xekhjw
- http://rentvspb.ru/dzduu
- http://revuk.com/agqrcwgqyn
- http://risewh.com/pg31nkp
- http://vedicmotet.com/4krn5d7
- http://vedicmotet.com/61y7mljr4
- http://vedicmotet.com/8eqb3u
- http://vedicmotet.com/rpi4l
- UPDATE:
- http://jinxlaze.com/1tsrnq7rqh
- http://nirvel.ca/7grdd
- http://nlvladimir.ru/sfmfl5ktuc
- http://ofertaestetica.com/5uiyuhohn
- http://orchideus.cz/vrzaq
- http://pineysprat.com/z2uqnic
- http://pnlglobal.com.au/i7uma
- http://polgraf.eu/j8uxdx0j
- http://prayerarchive.com/fymbob
- http://proancosl.com/gcotjy
- http://qumeinv.com/ljhdj5
- http://rennsteig-saale.de/pn7v5
- http://rightman.co.th/6vk5qq
- UPDATE2:
- http://natural-anxiety-remedies.com/e5vo06vkm
- http://oneice2011.com/4pwxwqj3ug
- http://pfec.com.au/mq2qf9eb
- http://pindaomenu.com/nvslt
- http://prismaserv.ro/obel8tf
- http://ptworkdomain.com/vicsc4zgya
- http://rek-style.ru/eivvpg7
- UPDATE3:
- http://ppfe.ru/vyf4h
- http://redrhinomakeuptrailers.com/jxgaeipxw
- http://naturalnepodlogi.cba.pl/utnnyduqa
- http://offerrat.com/12mi44q
- Malware:
- - encoded on download
- 540beef55a8adf2a14ba2acf48357433ca23291cb1859cad47c4229d9ae81f65 http___broncvita.com_5vy2q
- ab6b6a9e109ef7f7200fd5a4f92cceb64478bb24a4033b852194acd121857746 http___broncvita.com_dvdzv
- b06ddfacd055570a6ea817b1abfc03e65ff2b3edad2c068d546d8795ad5c5e56 http___broncvita.com_g7fiwm
- 793eb19fb4dd6b150bab5a9f86c23cceb7b32bc754b3088c5579652cd692872c http___broncvita.com_gy3defplbd
- a2050a09223d883232368daedfc64afeee92a875867a09779fcf8dfdd1df6d93 http___gurlfanam.net_bzv4jz9er
- 8bf47e6d3ae4168909eaae9dd2e28678a3b4ee994c0043669b28e43a7a49e467 http___gurlfanam.net_d4g73
- 6d0d9d9442973d90022afbe70e8e1332e3f61ec9f3fc763484c866752b97d63a http___gurlfanam.net_krwjx
- 64c83876303a741938aec86a7ca300c5a9ad1d6cb1d7ab9d6687aa15b6187ee9 http___gurlfanam.net_uhcgkozekr
- 56b345e29fbea43681fcb00bb8f037fb2f34e526496e6e1293a38e8cebb3095f http___jinxlaze.com_emch2nr6
- 9ca215fe1f19fc0d352d1ee337c1bd2c04f4959ed074f75cdb541ba4b6540af7 http___jinxlaze.com_rysuuttn
- 08ebf161edc68c6354fac7960f89935924f30c05dc094abf1d29b3c7842c1bed http___jinxlaze.com_vr2ltm
- 4bdc15d04a742fe23a7ddf88ba1808d1beb82a8b1141141d51b98f2d43c47cf0 http___nhatnang.vn_he5m5tfvih
- 9451f4c1903f45625c6cc11b113d6d31f5439ce138df69a480e04d7d86baf0a2 http___nicehdwall.com_lobvc
- d4fe0de9fb7c8827f4c0de5e72eea3497299ddb3677c90aba6d5cfa8d7d249d4 http___nielsredeker.nl_gmcoirnrm
- 37f21822c22f35aea14ec518782f7b3966a78bc5101f31d0030cf955d541df03 http___nightpeople.co.il_xklqq33nr
- d1c3c4bbc1fe106a7243d55186d64366579d3c653629f3420cb820b167d76f3d http___noveda.nl_viknlp3
- 351e188752f9a848b73b1944fe88be2045add5b4c13ddbe90f4d8d551e753a1c http___novinnic.ir_liinyes
- 70d2b911004d49f599f0fcb6a94e371f6b6233a9357e34f3b5b4e8255b9732ee http___obtenloya.com_iksivwr
- 571a4c0850c2d63791ce3fa61ac6a6270683bbafd1fb441289bcbc06849df0e0 http___ondeviesurgut.myjino.ru_4edogu
- 0a9a7f053020725b4b732f695ef34bf5368c3040081299af7874e920c6b63180 http___opakowania.info_ickljgo
- 8252fa8fd8d1bf48b690062f8bd81bede55e5a13f0ae5bc21ddebccb3e10a3bd http___opennano.pl_ewf1xe3i
- ab707c250ff7185c92f9dd903827c4e09d92249127a75637d9c2a797834640a1 http___ovacii.biz_eh7xryos [1]
- aaca2f1f670e481b158afb6f2352a8346f4870317092078c32011a58ffc209be http___ovofit.cz_tcaulm
- 74124182634b0b0207dc49226a5132a943f4dd894de6d904309c8d77261ff813 http___ozzu.de_wdxzw
- b338b5dbb65698b10a08d97892d6ff47347e7574198c99fefe4454aae26ede79 http___pearlgonzalez.com_b9wawhy
- 5c48729725c51b26ea15a28e17e52607aae2af003f7edfb33e253ae16819cbe4 http___pensionwoehler.de_9jjgk
- 033ec1a68d006f7885d52a7de5e636ce0de8506132c573d4a623617279bcf902 http___pesci.ro_jgves
- f26ef4b2169a38fe48bc8c5331e1b59f131e6a29a5443a7ce8d3b6c15c4148d4 http___pineysprat.com_fquah44d
- b0b2b1c98f84dfe646c2d3edbf2600a847fdb3f11cc4967c3ae9d1ddb6d5ecb1 http___pineysprat.com_jd3gfy
- 51fb5739514e788d27cf596d73616866be5af5876711b9f07e48147e662b9277 http___pineysprat.com_zqdjx
- 1affefb3fb145aa7526d10885808bd83a4c5da7311953bc6b6d3ceaaebd35386 http___playdog.ro_ufbuscn
- 0d36cf34911639a633545714b335d76f5b20e69fe3dcefc175402a1725266d4b http___playtres.com.ar_3aepw
- b0767e71b1e6d1d36e3f10024313e3d927d31b642aaae29c5c7c22049a892bee http___plus39italiandesign.com_rtyww0
- 536431f64eb1de48a7297dc94ad13daeaf809aa6a31ee13cbf9a030dc65fe4ac http___poloneo.com_55bgq
- 39e330258c60894773198057ab0cf11cd48728042f523350271895924fcc7a3d http___praam.cz_iessl
- 466f72275022b58fef6fa63d04e47797684abd89d2aa230d585c4e8412c91e20 http___pregnancysquare.com_diu9ktmd
- 119cab2876ecc200df3aa29cd8730dfedc5308431d8c7d5961217c8d51d683a5 http___printo.nl_uxzw0mspm
- ef2997f2a21162f03b005a045cb6b6ffe1e3d8c96bd88933cf50b622ca58d9b1 http___publygoo.it_u1rcrvfojx
- 496b7539755b3c3625dc49e6160b86a7fc46aa4cd6257a5fdbfa8fddc561b142 http___pvlabs.com_kby84bm
- 324405ee83f12baa3fa49c8034139222034ba95fdcf6b3cdf3095784db057527 http___qdweierya.com_qtubp
- ebdb8c638edd607866ca62c482a92b153cad55b3c517f4ce6c41c47667c3d5b1 http___rabavolgy.hu_utmu1mc
- 05c052b5827784d01fcec1905423dfeb85e66627150d77fff290803cbd12809e http___racersguide.com_ghsgpxzovg
- 94dd34cf12e133575efa1e8bb01bc17884d5b21e575e06f3f71b6ba1c0ad4623 http___reklomastik.com_8xekhjw
- a0fb65af4ac6f08b7f45ba3d43b05e120cff9fe92533407a87101f3eef22151d http___rentvspb.ru_dzduu
- abf41ce7b428fdbd5bcd624557a414a0ad1a50851471a0ef84ec50a1f2fbe17c http___revuk.com_agqrcwgqyn
- ce3a953795e98b735df5b597ec97dc13efd26ce830393b4702d449e45529203a http___risewh.com_pg31nkp
- 755cbef31a97f4dfb1d8c8e1f901fef5b1b476878ea0617cb04b6f12500a4372 http___vedicmotet.com_4krn5d7
- 24f95636c16ab7b7c1d5a742ff39c903dfd600ab01b5b276c3cc26efce3262e6 http___vedicmotet.com_61y7mljr4
- f7fa39b48d66ab99d430aac307fcfbfeeb1c8dff2f2a08050c222a66f45ced12 http___vedicmotet.com_8eqb3u [2]
- fa049ea855c58eb4b5c902455eac5402cfa5e83093411b17b32291671583e79d http___vedicmotet.com_rpi4l
- - decoded
- a62e526a4b17819de17846a44639cdce71de215a630cec1487fea86271e6e8a0 [1]
- 7381969a2409f5b99a9f6d78a1fe632c4d845a11033cd4f972f9e6025e3553d2 [2]
- - executed by "rundll32.exe %TEMP%\<dll_name>,mq"
- C2:
- POST http://195.123.209.8/information.cgi
- POST http://213.32.66.16/information.cgi
- POST http://95.213.186.93/information.cgi
- POST http://hatjmumvu.su/information.cgi
- POST http://icjrdsuouoxjxref.click/information.cgi
- POST http://jbjolaaxwgudt.org/information.cgi
- POST http://myqbrkhlj.su/information.cgi
- POST http://oaflyjmei.click/information.cgi
- POST http://oeeqvvarhgiqmao.work/information.cgi
- POST http://opjhubsyxj.xyz/information.cgi
- POST http://trqrhxbooviphgk.ru/information.cgi
- POST http://ybokmaqgxqdf.biz/information.cgi
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement