Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-10-11: #locky & #trickbot email phishing campaign "Emailing: xxxxxxxx"
- Email sample:
- ------------------------------------------------------------------------------------------------------------------------------
- From: "Elma" <Elma.Sturrock@primaaccounting.co.uk>
- To: [REDACTED]
- Subject: Emailing: 28294013
- Date: Wed, 11 Oct 2017 11:33:52 -0600
- Your message is ready to be sent with the following file or link
- attachments:
- 28294013
- Note: To protect against computer viruses, e-mail programs may prevent
- sending or receiving certain types of file attachments. Check your e-mail
- security settings to determine how attachments are handled.
- Attachment: 28294013.7z -> 409112229.vbs
- ------------------------------------------------------------------------------------------------------------------------------
- - subject is "Emailing: <8-9 digits>"
- - attached file "<8-9 digits>.7z" contains file "<8-9 digits>.vbs", a VBScript downloader, which will for UK, AU, LU, BE and IE download Trickbot and for other countries Locky malware from the following links:
- Trickbot download sites:
- http://agriturismoviridarium.it/6jbgcfwe3
- http://enixgaming.de/6jbgcfwe3
- http://enmee.net/6jbgcfwe3
- http://fetchstats.net/p66/6jbgcfwe3
- http://fls-portal.co.uk/6jbgcfwe3
- http://jeangurunlian.com/6jbgcfwe3
- http://peopleiknow.org/6jbgcfwe3
- http://petrochemus.com/6jbgcfwe3
- http://sci-eye.com/6jbgcfwe3
- http://secundaria50.edu.mx/6jbgcfwe3
- http://stemcellenhancementresearch.com/6jbgcfwe3
- Locky download sites:
- http://alexandradickman.com/cunrb78f
- http://arkberg-design.fi/cunrb78f
- http://basedow-bilder.de/cunrb78f
- http://centralbaptistchurchnj.org/cunrb78f
- http://download.justowin.it/cunrb78f
- http://fetchstats.net/p66/cunrb78f
- http://hair-select.jp/cunrb78f
- http://itsmaterial.us/cunrb78f
- http://lacosturera.es/cunrb78f
- http://missiegeslaagd.nl/cunrb78f
- http://motifahsap.com/cunrb78f
- http://pacalik.net/cunrb78f
- http://ryanbaptistchurch.com/cunrb78f
- http://sambad.com.np/cunrb78f
- http://sgtenterprises.com/cunrb78f
- http://shamanic-extracts.biz/cunrb78f
- http://signlight.com.au/cunrb78f
- - trickbot
- - SHA256: 79a40ac47ea2b57727437a7a9365e860cc1fa1c7c96900f5a2a90133959c4694, MD5: e3d2e5e74874fd8b59ddef544f7e4851
- - VT: https://www.virustotal.com/en/file/79a40ac47ea2b57727437a7a9365e860cc1fa1c7c96900f5a2a90133959c4694/analysis/1507746825/
- - HA: https://www.reverse.it/sample/79a40ac47ea2b57727437a7a9365e860cc1fa1c7c96900f5a2a90133959c4694?environmentId=100
- - locky ransomware, offline asasin variant
- - SHA256: 1d4a3957a4f4d83f1edffcb0b596e04d98c82f801ae4b23208a34076203f42f6, MD5: c77d1c0c0ecd0b2f81f2bcf89fb07279
- - VT: https://www.virustotal.com/en/file/1d4a3957a4f4d83f1edffcb0b596e04d98c82f801ae4b23208a34076203f42f6/analysis/1507743328/
- - HA: https://www.reverse.it/sample/1d4a3957a4f4d83f1edffcb0b596e04d98c82f801ae4b23208a34076203f42f6?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement