SHARE
TWEET

2017-10-10 Locky "Voicemail From 845-551-NNNN"

Racco42 Oct 10th, 2017 929 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2017-10-10: #locky email phishing camapign "Voicemail From 845-551-NNNN"
  2.  
  3. Email sample:
  4. -----------------------------------------------------------------------------------------------------------------------
  5. Date: Tue, 10 Oct 2017 21:38:26 +0530
  6. From: Microsoft Voice <MSVoice@dhl.com>
  7. Subject: Voicemail From 845-551-2955
  8.  
  9. Voice Message received at Tue, 10 Oct 2017 21:38:26 +0530
  10. Voicemail Length 39 sec
  11.  
  12. Attached: VMSG9814443_20171010.7z -> VMSG398056009_20171010.vbs
  13. -----------------------------------------------------------------------------------------------------------------------
  14. - sender name is "Microsoft Voice" and email address is forged to look like coming from recipient's domain MSVoice@domain
  15. - subject is "Voicemail From 845-551-<4 digits>"
  16. - email does not have To: header
  17. - attached file "VMSG<5-10 digits>_20171010.7z" contains file "VMSG<9-11 digits>_20171010.vbs, a VBScript downloader
  18.  
  19. Download sites:
  20. http://alucmuhendislik.com/njhgftrf3
  21. http://atlantarecyclingcenters.com/njhgftrf3
  22. http://bit-chasers.com/njhgftrf3
  23. http://bjp.co.id/njhgftrf3
  24. http://centurythis.com/njhgftrf3
  25. http://estudiperceptiva.com/njhgftrf3
  26. http://handhi.com/njhgftrf3
  27. http://hellonwheelsthemovie.com/njhgftrf3
  28. http://hexacam.com/njhgftrf3
  29. http://logica-info.com/njhgftrf3
  30. http://mh-service.ru/njhgftrf3
  31. http://miamirecyclecenters.com/njhgftrf3
  32. http://monstermx.com/njhgftrf3
  33. http://m-tensou.net/njhgftrf3
  34. http://nsaflow.info/p66/njhgftrf3
  35. http://paulcruse.com/njhgftrf3
  36. http://suncoastot.com/njhgftrf3
  37.  
  38. Malware
  39. - locky ransowmare, offline .asasin variant
  40. - SHA256 a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7, MD5: 37c106c0d8e97fbe9ec10a037858ea23
  41. - VT: https://www.virustotal.com/en/file/a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7/analysis/1507651868/
  42. - HA: https://www.reverse.it/sample/a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7?environmentId=100
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top