Advertisement
Racco42

2017-10-10 Locky "Voicemail From 845-551-NNNN"

Oct 10th, 2017
3,497
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.91 KB | None | 0 0
  1. 2017-10-10: #locky email phishing camapign "Voicemail From 845-551-NNNN"
  2.  
  3. Email sample:
  4. -----------------------------------------------------------------------------------------------------------------------
  5. Date: Tue, 10 Oct 2017 21:38:26 +0530
  6. From: Microsoft Voice <MSVoice@dhl.com>
  7. Subject: Voicemail From 845-551-2955
  8.  
  9. Voice Message received at Tue, 10 Oct 2017 21:38:26 +0530
  10. Voicemail Length 39 sec
  11.  
  12. Attached: VMSG9814443_20171010.7z -> VMSG398056009_20171010.vbs
  13. -----------------------------------------------------------------------------------------------------------------------
  14. - sender name is "Microsoft Voice" and email address is forged to look like coming from recipient's domain MSVoice@domain
  15. - subject is "Voicemail From 845-551-<4 digits>"
  16. - email does not have To: header
  17. - attached file "VMSG<5-10 digits>_20171010.7z" contains file "VMSG<9-11 digits>_20171010.vbs, a VBScript downloader
  18.  
  19. Download sites:
  20. http://alucmuhendislik.com/njhgftrf3
  21. http://atlantarecyclingcenters.com/njhgftrf3
  22. http://bit-chasers.com/njhgftrf3
  23. http://bjp.co.id/njhgftrf3
  24. http://centurythis.com/njhgftrf3
  25. http://estudiperceptiva.com/njhgftrf3
  26. http://handhi.com/njhgftrf3
  27. http://hellonwheelsthemovie.com/njhgftrf3
  28. http://hexacam.com/njhgftrf3
  29. http://logica-info.com/njhgftrf3
  30. http://mh-service.ru/njhgftrf3
  31. http://miamirecyclecenters.com/njhgftrf3
  32. http://monstermx.com/njhgftrf3
  33. http://m-tensou.net/njhgftrf3
  34. http://nsaflow.info/p66/njhgftrf3
  35. http://paulcruse.com/njhgftrf3
  36. http://suncoastot.com/njhgftrf3
  37.  
  38. Malware
  39. - locky ransowmare, offline .asasin variant
  40. - SHA256 a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7, MD5: 37c106c0d8e97fbe9ec10a037858ea23
  41. - VT: https://www.virustotal.com/en/file/a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7/analysis/1507651868/
  42. - HA: https://www.reverse.it/sample/a165963bb5575321c03f974e266808d34b695fa21d0f2dd96a66cd3c887bd5e7?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement