Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-12-14: #locky email phishing campaign "Amount Payable"
- Email sample:
- ---------------------------------------------------------------------------------------------------------------------
- From: "Normand Landry" <Landry.Normand@quakenet.ro>
- To: [REDACTED]
- Subject: Amount Payable
- Date: Thu, 15 Dec 2016 00:57:21 +0430
- Dear [REDACTED],
- The amount payable has come to $38.29. All details are in the attachment.
- Please open the file when possible.
- -
- Best Regards,
- Normand Landry
- Attachment: doc_1788897.zip -> ~_A5TNJ_~.js
- ---------------------------------------------------------------------------------------------------------------------
- - sender varies between emails
- - subject is "Amount Payable"
- - attached file "doc_<7 digits>.zip" contains file "~_<5-7 uppercase chars and digits>_~.js", a JScritp downloader
- Download sites:
- http://0668.com/k5bhgn
- http://250sb.com./jynvmx
- http://addwords.com.tr/aah6qmhv
- http://anti-dust.ru/7k6cp
- http://asdream.pl/gbbs1c
- http://atio.li/exjik
- http://bappeda.dharmasrayakab.go.id/dlhalychp
- http://braindouble.com/uycx51ix
- http://buhoutserts.ru/ufdazc6vv
- http://casino-okinawa.com/ejguf
- http://catherineduret.ch/5qpqi5ezp
- http://chinaxw.org/xw1ju7y6zc
- http://chungcuvinhomemydinh.com/6dvjasf
- http://crolic88.myjino.ru/1ddig
- http://demo.shispare.com/bvsjq
- http://environment.ae/0od5hn
- http://forbrent.com/h9kqgq
- http://fyd123.cn/kib6h2d9ga
- http://groupeelectrogeneservice.com/eefpeywf9z
- http://hedefosgb.com/dpyzsb6u
- http://hlonline.kentucky.com/i7z78
- http://innercityarts.squaremdesign.com/dyo1w7
- http://jianhu365.com/z9puqdj2eu
- http://malamut.org/gizb2zq
- http://obaloco.com.br/67mfj
- http://peopleprofit.in/pyihdg
- http://roman64.humlak.cz/7bnisgf
- http://rulebraker.ru/zsw4cnf9o
- http://scaune.qmagazin.ro/5hktu4h
- http://slankmethode.nl/4zzq1am
- http://subys.com/mjguriv80
- http://szwanrong.com/x5qxzpjsi
- http://tecnomundo.uy/a8rnlgzv
- http://test1.giaiphaponline.org/0ytdjs1
- http://test.sousouyo.com/feaetpnuee
- http://theamericanwake.com/xw1ju7y6zc
- http://travelinsider.com.au/mwaefb4b
- http://trietlong.net/heyus
- http://tx318.com/kqe4ca
- http://ucbus.net/usdxqqt6
- http://u-niwon.com/kmjg6j9ske
- http://vaaren.dk/ogcz6ys0d
- http://viscarci.com/wyqs6353
- http://walkonwheels.net.au/qmd1uu
- http://wdcd999.com/lm5z2snyqn
- http://web-shuttle.in/eeo9oc
- http://windshieldrepairvancouver.ca/qcp8k7
- http://wiselysoft.com/qcymgbug7
- http://wszystkodokuchni.pl/sl5yko7
- http://wudiai.com/mc3hnwd
- http://www.espansioneimmobiliare.com/akktnck
- http://www.myboatplans.net/6d7ukeco6
- http://wx.utaidu.com/1eybujbru
- http://xlr8services.com/n970foumf
- http://xn--k1affefe.xn--p1ai/8wzzjk24u
- http://youspeak.pt/liowrtxs
- http://yukngobrol.com/h7sfu
- http://zhiyuw.com/qfbdcvrul
- http://zwljfc.com/ld1pvjozu
- http://zzzort10xtest123.com/nin5k3bwo
- Malware:
- - encoded on download
- 60380d4f3e5e392d7af27bc85324d7363dd644dfce4059bff832bb3dff17ff21 http___0668.com_k5bhgn
- 137687d668b7b4b8039f0b373f92c7b84b5c49f14c64d2f9982737b7cdcc1db7 http___250sb.com._jynvmx
- 65941d887fb447f13b551c295b784374fd834fabafbf7266ceea19b8ff6e8331 http___addwords.com.tr_aah6qmhv
- 1333357356f93875d1831193aa25fb1ff4bd6c0f04b9c1b971ef7a30cddf50b6 http___anti-dust.ru_7k6cp
- 3fbff9869e61846c60b500090daa34dcdedcef59940d50b7e94efad20f4af24e http___asdream.pl_gbbs1c
- 5c51485c89adcc9d3e174021495b459e3e635e7935c3a4943fee691fa28f1495 http___atio.li_exjik [1]
- 74e94c4b500b9ad64afed2db0614c4d74c819f70f42d17db7bb44d383427fb02 http___bappeda.dharmasrayakab.go.id_dlhalychp
- 31c0582fe008bd0c689c5416b51dea3da31c9f19557d47cad2a2a73bb7c67389 http___braindouble.com_uycx51ix
- f4a1f90ba4c2f8c17591293d5cb23487e352292c4fe0670f323d33c64ffa0b43 http___buhoutserts.ru_ufdazc6vv
- ca367a9dc60404345f4378e16748bfc9eb9f6f3b5bdc9d3193b7ba4d6b1b4b71 http___casino-okinawa.com_ejguf
- 6c27687cc69afbca322a0f553af13a259ee0cd962bc43a570d9b42558775cf54 http___catherineduret.ch_5qpqi5ezp
- 5abf81af30ac919aa98d6451ad464bd1889f6923d038bfe0e3c806bd7aa8890c http___chungcuvinhomemydinh.com_6dvjasf
- 51d8b0e56378efdf337697aababb3d2860411aa207124251989974e48fdb6974 http___crolic88.myjino.ru_1ddig
- f6dd414b3baac81d6c76b19a437a8d881b9ae316f2894c9a350841f587d983fb http___demo.shispare.com_bvsjq
- 65803aaa66bc6a101729b223c9c6d35561bb2eb04ac109b72253645a330cfba2 http___environment.ae_0od5hn
- f88b7dd4a3bc6ffa0acbb484d1f8a9a0487c46d2900a47580f50349cd1e2c588 http___forbrent.com_h9kqgq [2]
- eef9ad652b13df46397bf0ebbf48058d5e3fe5ac05d8a0b1e9a1341133740260 http___fyd123.cn_kib6h2d9ga
- 24e0ce5b7e72f05e41c122c2743af3baa828ca0542af734607ab6bd11b6e1487 http___groupeelectrogeneservice.com_eefpeywf9z
- 63dfe370502acd3b78fc48c0ce11bf9d8e35b2fab53f949214a96e734bb34a68 http___hedefosgb.com_dpyzsb6u
- 94e1b546c26c96550df3d95b5efbbf420382e31537999b2014771597afc60fd1 http___hlonline.kentucky.com_i7z78
- 45a4f3987d25ff1d00fedd3310dc755c555149b9a0595178ccd546002157a23e http___innercityarts.squaremdesign.com_dyo1w7
- cfaa1aee8b07a41975bc9e53bb863f3b058bcde0de9bcc217067673fcc27dbc0 http___malamut.org_gizb2zq
- 7260fd1b41a23694c54866b0053c46d4a0412d42c75839117f5b8ddd707217ad http___obaloco.com.br_67mfj
- 53104b5ea46bad10353f24f312aac4facfaea2381dba48297592bb3df0e18c55 http___peopleprofit.in_pyihdg
- 8fb7d12dd09f3dda073ece619a5d7f82c96d5d04598919afe65fdae0dd7b208c http___roman64.humlak.cz_7bnisgf
- 1552dbbe4dc744872eca7fb0e35b256c18ca576d50c23b38a93f5adfe40e2db0 http___rulebraker.ru_zsw4cnf9o
- 38e159af864c3625b86ae8b01119318c193e1fecf94bd5533d735fa85d3e1fec http___scaune.qmagazin.ro_5hktu4h
- f425067875dfa1ef54d3e8519e9a20a7368b31fb5458eef17b74ce41c236b3db http___slankmethode.nl_4zzq1am
- 17d7054854256b0793bf6aa6700546a043e972191bba20145946a6902d1c9007 http___subys.com_mjguriv80
- 0df5f4a1e05ad5b4289c45bd08ab5645519e10c9ccd82b00e10312fa15258b11 http___szwanrong.com_x5qxzpjsi
- e9719d8d73558beefb8d5a706d2c05169cea4e98aecea19df43c8d2f0023f384 http___tecnomundo.uy_a8rnlgzv
- 218fd633ecd4b10003690aac020245b23f7670d143dc508d84abf95c2da60077 http___test1.giaiphaponline.org_0ytdjs1
- f96ba5acf26cdb1abd679b7f66d4aec67e2c64dc9d15eea0e822c16385aa7155 http___test.sousouyo.com_feaetpnuee [5]
- cfaa1aee8b07a41975bc9e53bb863f3b058bcde0de9bcc217067673fcc27dbc0 http___theamericanwake.com_xw1ju7y6zc
- 99b654d39413500f0255c6bd900251462847a8d0bc0eff5ad699efda157607d8 http___travelinsider.com.au_mwaefb4b
- 0ae9b763c4332641b021705d38b5db32088abe19ef0bfdef360e9df50c396ea2 http___trietlong.net_heyus
- 37f5ce8fcb00a1152835efdaac775d33cf5e51eba909fc6a0b363f25bb4d84db http___tx318.com_kqe4ca
- 15573792ae1923c24ac9ea35b81d39670ae0d002f74ca12ab59a8025318b0db6 http___ucbus.net_usdxqqt6 [3]
- e421ff2290f3660bd93bc353852719377cf94a8558779fb3b3307d9855251743 http___u-niwon.com_kmjg6j9ske
- fac51ac31cbe2cabc4a1aead779c328ebc6929e286b1e8dfb0928afaca3fee88 http___viscarci.com_wyqs6353
- 7942fb56210c40a5335a1d27a7b71adfff2faa10cd0e15d3b6b94092f450fc40 http___wdcd999.com_lm5z2snyqn
- 9c56960f149aaaa338846b2044bcb33bc410a1c07e4c6fae305b4f530744b5dc http___web-shuttle.in_eeo9oc
- 4b628c53cc41568c3404342ed95b9f2ee0757536ce0cf4ce8bc840829552c22e http___windshieldrepairvancouver.ca_qcp8k7
- 5487e861fc020735a22fa2270413ac0ecd67312d64ab6e3f4fe049247c37c05d http___wiselysoft.com_qcymgbug7
- 0b962425f88cb33bb6f1f749b6c51445f4355e2977dbe09d14e0793c2460eaa7 http___wszystkodokuchni.pl_sl5yko7 [4]
- 4977658adcd5be63bf67d4467703596a7440419539c781d13ac0c2907e9b4aff http___wudiai.com_mc3hnwd
- 5efbd6851f53e4dc744b3c2668190604da054cc032cdc9a8c374c6da485d6cd4 http___www.espansioneimmobiliare.com_akktnck
- 61e1f8f7de66c5c47bfa650a32350ddb1e6e9d276f2ab4000fbed8ab040af6f3 http___www.myboatplans.net_6d7ukeco6
- 653cec019e34af43b585f53fd2314c7c1be5665f839a24b83cf9aa77d168c00c http___wx.utaidu.com_1eybujbru
- c079b2076b743b9330f516d6b3ad70d4f6814a75fadc9193eb8831b80f5cd195 http___xlr8services.com_n970foumf
- 77002e17bf31f497f8b3af7eba5784189b3d8ac17544716c896b8b6524051a57 http___xn--k1affefe.xn--p1ai_8wzzjk24u
- 09f320f6075ef76a0b4872e4c254d0a7232166a45d68d9343c052a44ae895b3e http___yukngobrol.com_h7sfu
- 86c7448570c0de7abdfcaaea5fb629e33ea92243c4e29ff40e6c945d2a866d54 http___zhiyuw.com_qfbdcvrul
- 492331c3a61cc62aaa474ef138c3cd061c1d24c3cee4df15d94c5e31c290079b http___zwljfc.com_ld1pvjozu
- e421ff2290f3660bd93bc353852719377cf94a8558779fb3b3307d9855251743 http___zzzort10xtest123.com_nin5k3bwo
- - decoded
- 266aac2adca47cd8c39fa190faf70e32dd1a2752eee22ada4b7fe1a0c80366e3 [1]
- d44ff3a846a7e5333f6c53e62225760023ffc0629f6dca2adc2256ab2d232854 [2]
- 4140fa2ea07aab513f2ecd8ccd99a079105ae39e3c2b0cccd225a5354a75c999 [3]
- 3ad4d594c184f832277dafdee24a3a3a6e8911fb58f0c2b6afdd8cf33549b59b [4]
- d188b1e1ad3bac313944e30b2ef8e562dced670830e443dc2057bd377494a3ab [5]
- - executed by "rundll32.exe %TEMP%\<filename>.ZK,S6jdvsfFR"
- - samples:
- https://www.virustotal.com/file/266aac2adca47cd8c39fa190faf70e32dd1a2752eee22ada4b7fe1a0c80366e3/analysis/1481756885/
- https://www.virustotal.com/file/d44ff3a846a7e5333f6c53e62225760023ffc0629f6dca2adc2256ab2d232854/analysis/1481756895/
- https://www.virustotal.com/file/4140fa2ea07aab513f2ecd8ccd99a079105ae39e3c2b0cccd225a5354a75c999/analysis/1481756920/
- https://www.virustotal.com/file/3ad4d594c184f832277dafdee24a3a3a6e8911fb58f0c2b6afdd8cf33549b59b/analysis/1481756940/
- https://www.virustotal.com/file/d188b1e1ad3bac313944e30b2ef8e562dced670830e443dc2057bd377494a3ab/analysis/1481756962/
- C2:
- POST http://185.129.148.56/checkupdate
- POST http://185.17.120.166/checkupdate
- POST http://86.110.117.155/checkupdate
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement