Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2016-11-01: #locky email phishing campaign "Invoice No. xxxxxxxx for <recepient>"
- Email sample:
- -------------------------------------------------------------------------------------------------------------------
- From: <info@[REDACTED]>
- To: [REDACTED]
- Subject: Invoice No. 50543846 for [REDACTED]
- Date: Tue, 01 Nov 2016 06:18:27 -0700
- REF: 10652342
- INVOICE NUMBER: 50543846
- FROM: Vincent & Gorbing (175-187 Linthorpe Road,Buxton, Derbyshire, SK179QF, UNITED KINGDOM)
- DATE: 01/11/2016
- ---------------------------------
- This is an automated message generated by the Banana ERP Accounting.
- Any questions? Reply to this e-mail address. Do not hesitate to contact us.
- Attachment: INV_NO_50543846.zip
- -------------------------------------------------------------------------------------------------------------------
- - sender address is faked as coming from info@<recipient's domain>
- - subject is "Invoice No. <8 digits> for <recipient email without domain>"
- - attached file "INV_NO_<digits>.zip" contains file "INV_NO_<digits>.wsf", a JSCript downloader
- Download sites (the actual URLs contains suffix ?<random>=<random> which does not influence the download):
- http://1000i.co/87yfhc
- http://33173.com/87yfhc
- http://adriandomini.com.ar/87yfhc
- http://agorarestaurant.ro/87yfhc
- http://amediacanarias.com/87yfhc
- http://anagrual.es/87yfhc
- http://arburton.com/87yfhc
- http://arrefrigeracao.com.br/87yfhc
- http://asiawing.com/87yfhc
- http://asirio.es/87yfhc
- http://asylinfo.de/87yfhc
- http://avbonline.nl/87yfhc
- http://avon2you.ru/87yfhc
- http://avpschool.org/87yfhc
- http://ayurvedic.by/87yfhc
- http://bakfon.az/87yfhc
- http://bappeda.palangkaraya.go.id/87yfhc
- http://basis12.ru/87yfhc
- http://bbdogalgaz.com/87yfhc
- http://bg-globalmarketing.com/87yfhc
- http://bielpak.pl/87yfhc
- http://bijansartorial.com/87yfhc
- http://bjxdsm.com/87yfhc
- http://cavieuredo.net/87yfhc
- http://chinaeyes.net/87yfhc
- http://cidadehoje.pt/87yfhc
- http://city-hospital.com/87yfhc
- http://codanuscorp.com/87yfhc
- http://comdatex.de/87yfhc
- http://comercialzamora.es/87yfhc
- http://comovan.t5.com.br/87yfhc
- http://computerhome.lu/87yfhc
- http://csepelihaziko.hu/87yfhc
- http://cted.pt/87yfhc
- http://dbs.mx/87yfhc
- http://deepwellsenergy.com/87yfhc
- http://designercabochons.co.uk/87yfhc
- http://dmamart.com/87yfhc
- http://doggytalk.be/87yfhc
- http://domain4all.gr/87yfhc
- http://drevenesochy.eu/87yfhc
- http://drmulchandani.com/87yfhc
- http://dulich.me/87yfhc
- http://eadmin.cz/87yfhc
- http://edubit.eu/87yfhc
- http://englishstate.com/87yfhc
- http://eroger.be/87yfhc
- http://esustentables.com.ar/87yfhc
- http://fanpool.ru/87yfhc
- http://farmgirlpoems.com/87yfhc
- http://haushisn.com/87yfhc
- http://land.14-18.ru/87yfhc
- http://pornovizion.com/87yfhc
- http://topsng.ru/87yfhc
- Malware:
- - encoded on download, SHA256 df730cd35d525c64f45a6134b75e8ae13412736289bc81a283c71d9a9e5b1275, filesize 249856 bytes
- - decoded SHA256 a671f6b8f2af3235f0d76e24278658d3d5598eb24a530a9fa5f4e44bc7fa5ece
- - samples
- https://malwr.com/analysis/NTJiNjJhODQxYWU0NGNjYTg5N2E1YTA2OWIxNzVhYTE/
- https://malwr.com/analysis/NzVhNmQyZWYyNmNhNDZjZjk3NDI1NTdhYTM5M2QxMDU/
- https://malwr.com/analysis/MzI5Y2ZjODlhODRjNDY2Y2ExMmNlMGFjYzcwMjE3ZDc/
- https://malwr.com/analysis/MDgyM2I0NzM2ZGI5NDM4ZmE1N2ZlOGQyNDU4NzFiZjQ/
- C2:
- http://51.255.107.20/linuxsucks.php
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement