Advertisement
Racco42

2016-11-08 Locky "Statement"

Nov 8th, 2016
2,947
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.01 KB | None | 0 0
  1. 2016-11-08 #locky email phishing campaign "Statement"
  2.  
  3. Email sample:
  4. -------------------------------------------------------------------------------------------------------
  5. From: <accounts@bonniebarbieri.com>
  6. To: [REDACTED]
  7. Subject: Statement
  8. Date: Tue, 08 Nov 2016 13:34:17 +0330
  9.  
  10. For your Information.
  11.  
  12. Attachment: "Statement PDF - 51707599835.zip"
  13. -------------------------------------------------------------------------------------------------------
  14. - sender address is "accounts@<random domain>"
  15. - subject is "Statement"
  16. - attached file "Statement PDF - <random numbers>.zip" contains file "<3 letters><5-6 digits>-<4 digits>.wsf", a JSCript downloader
  17.  
  18. Download sites (actual URLs contain suffix ?<random>=<random> which does not influence download):
  19. http://alamanconsulting.at/67j5hg
  20. http://all-kaigo.com/67j5hg
  21. http://arabom.com/67j5hg
  22. http://bmkgjateng.com/67j5hg
  23. http://dhmodel.cz/67j5hg
  24. http://fitnessrelax.sk/67j5hg
  25. http://focovi.cl/67j5hg
  26. http://frivill.hu/67j5hg
  27. http://fsgbly.com/67j5hg
  28. http://fu-k.jp/67j5hg
  29. http://fulltattoo.com/67j5hg
  30. http://fungasoap.net/67j5hg
  31. http://futurovision.com/67j5hg
  32. http://g2m.pl/67j5hg
  33. http://gaestehaus-kellner.de/67j5hg
  34. http://galebtopola.com/67j5hg
  35. http://gambit.nysa.com.pl/67j5hg
  36. http://gentscha.de/67j5hg
  37. http://geodispo.com/67j5hg
  38. http://giasungoaingu.net/67j5hg
  39. http://gigabothosting.com/67j5hg
  40. http://gingell.ca/67j5hg
  41. http://giochasach.com/67j5hg
  42. http://gisinecology.com/67j5hg
  43. http://glassfusing.com.au/67j5hg
  44. http://golden-bereg.ru/67j5hg
  45. http://gpstrackerbali.com/67j5hg
  46. http://grafa.cz/67j5hg
  47. http://grahamkennedy.ca/67j5hg
  48. http://greatmeeting.org/67j5hg
  49. http://greenmodul.com/67j5hg
  50. http://greenoceanpetroleum.com/67j5hg
  51. http://greentic.univcasa.ma/67j5hg
  52. http://grplink.com/67j5hg
  53. http://guneynakliyat.net/67j5hg
  54. http://gushifengyun.com/67j5hg
  55. http://gxhedu.net/67j5hg
  56. http://hamburyhird.co.uk/67j5hg
  57. http://hamidrukkers.nl/67j5hg
  58. http://hanak-nafotil.kvalitne.cz/67j5hg
  59. http://haneyslanding.com/67j5hg
  60. http://happyrushop.com/67j5hg
  61. http://havaa.nl/67j5hg
  62. http://hcunit.com/67j5hg
  63. http://helfter.fr/67j5hg
  64. http://hgqcqc.com/67j5hg
  65. http://highlandsolar.ca/67j5hg
  66. http://hightradingfrequency.com/67j5hg
  67. http://hirdavatix.com/67j5hg
  68. http://h-miyoshi.ed.jp/67j5hg
  69. http://hobbis.cz/67j5hg
  70. http://hubbambaya.net/67j5hg
  71. http://interprofil.no/67j5hg
  72. http://inzt.net/67j5hg
  73. http://iwebsdns.com/67j5hg
  74. http://kekjacint.hu/67j5hg
  75. http://kongogene.com/67j5hg
  76. http://monowheels.ru/67j5hg
  77. http://omidak.ir/67j5hg
  78. http://restaurant-traditional.ro/67j5hg
  79. http://shopey.net/67j5hg
  80. http://vikingradom.freehost.pl/67j5hg
  81. http://wilson.ro/67j5hg
  82.  
  83. UPDATE:
  84. http://fourpair.com/67j5hg
  85. http://gomuskegon.mobi/67j5hg
  86. http://gremr.ma/67j5hg
  87. http://sungbocne.com/67j5hg
  88.  
  89. UPDATE:
  90. http://chuzhang.net/67j5hg
  91. http://cxsd.com.cn/67j5hg
  92. http://funkybytes.fr/67j5hg
  93. http://funtasy.be/67j5hg
  94. http://futureartdesign.ro/67j5hg
  95. http://gocascadia.com/67j5hg
  96. http://goldensail.ru/67j5hg
  97. http://gold-or.ca/67j5hg
  98. http://mgpu.gomel.by/67j5hg
  99.  
  100.  
  101. Malware:
  102. - encoded on download, SHA256 da490b31aea1775216e95c036a311dd56cad99f8848230caaf89d7450a5471a3, MD5 4164b4a9b8a8c3bfc0effd3b7dbfd6f7
  103. - decoded SHA256 7e6c08f576eeef7c44558fdfc8c6961de15d16d15ab5cf8615951084a5960007, MD5 ed5eee4f7d209413bc8ef139f448e12d
  104. - executed by "rundll32 %TEMP%\<dll_name>,set"
  105. - samples:
  106. https://www.reverse.it/sample/44f87f0bafd325e02655b6f407df3656d59b762acf02ef1178f828d7d2c9b0f0?environmentId=100
  107. https://www.reverse.it/sample/025a3e2f1ccbd10cbce15ab84ba91a029930e2ea5d3c9ab217a8cfe1f2168638?environmentId=100
  108. https://www.reverse.it/sample/ab097596e05ab96cf484a15f3eed0d687a042a949a5bf2af66dbca72dc29f776?environmentId=100
  109. https://www.reverse.it/sample/0732a12bff0b1985bdaf322fb00345680bd1ff8f7babb6c2ad8b6d0ca987acfd?environmentId=100
  110.  
  111. C2:
  112. POST http://158.69.223.5/message.php
  113. POST http://185.118.66.90:80/message.php
  114.  
  115. bnmqkgdlotrwqym.work
  116. dmynnrrvse.org
  117. gccaoqb.xyz
  118. jcbbccd.pl
  119. ksrcvmvfbc.org
  120. ornrkiokjkkqymw.org
  121. mwyryuxoyhxlk.work
  122. ummprtrxunm.xyz
  123. wmstntaae.su
  124. wmcrfvhf.org
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement