Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2019-06-20 - MALSPAM PUSHING NANOCORE RAT
- - Attachement: Reciept.img (SHA256 hash: 9378d39b2abd8ee5acbf2d860bd0559134d9ce514c281c41f509638bd9d77a14)
- - Extracted file: Reciept.scr (SHA256 hash: dddf971a52e4fc7635c72292a06fc7ed8e41bec5157b0032acb7a20347f37921)
- -- Any.run analysis of extracted file: https://app.any.run/tasks/e1807028-57ec-4519-995a-af73daf6d8e4
- EMAIL:
- X-Originating-Ip: [65.52.234.16]
- Authentication-Results: [removed].rsapps.net; iprev=pass policy.iprev="65.52.234.16"; spf=softfail smtp.mailfrom="contact@azure.com" smtp.helo="mysmtp1.northcentralus.cloudapp.azure.com"; dkim=none (message not signed) header.d=none; dmarc=fail (p=none; dis=none) header.from=azure.com
- Received: from [65.52.234.16] ([65.52.234.16:36610] helo=mysmtp1.northcentralus.cloudapp.azure.com) by [removed]
- (envelope-from <contact@azure.com>) [removed]; Thu, 20 Jun 2019 07:19:58 -0400
- Received: from MYRDP.shy1v4l2bkuuxjgwhhbgqcdz4c.jx.internal.cloudapp.net (unknown [104.214.58.211])
- by mysmtp1.northcentralus.cloudapp.azure.com (Postfix) with ESMTPA id CB2BA2210EE3;
- Thu, 20 Jun 2019 11:19:51 +0000 (UTC)
- Message-ID: <EE.05.17125.EDB6B0D5@smtp32.gate.ord1d.rsapps.net>
- Content-Type: multipart/mixed; boundary="===============0376729141=="
- MIME-Version: 1.0
- Subject: =?utf-8?b?UGF5bWVudMKgQW1vdW50IDogwqBVU0QgJDEwLDcyNy4xMQ==?=
- To: Recipients <contact@azure.com>
- From: "Azure Enterprise (S) Pte Ltd" <contact@azure.com>
- Date: Thu, 20 Jun 2019 11:19:51 +0000
- You will not see this in a MIME-aware mail reader.
- --===============0376729141==
- Content-Type: multipart/alternative; boundary="===============0675389668=="
- MIME-Version: 1.0
- --===============0675389668==
- Content-Type: text/plain; charset="iso-8859-1"
- MIME-Version: 1.0
- Content-Transfer-Encoding: quoted-printable
- Content-Description: Mail message body
- Dear contact,
- Payment will be completed when you confirm the attached application form =
- Once verified, it will be credited to your account =
- Payment Details attached....
- Date : June, 17, 2019
- Receipt Number : 0C739415OU953045R
- Payment Amount : USD $5,727.11
- Payment Status : Pendng
- =
- complete the Payment application form in attachment
- =
- For assistance contact =
- Best Regards,
- --===============0675389668==
- Content-Type: text/html; charset="iso-8859-1"
- MIME-Version: 1.0
- Content-Transfer-Encoding: quoted-printable
- Content-Description: Mail message body
- <HTML><head><meta http-equiv=3D"Content-Type" content=3D"text/html; charset=
- =3Diso-8859-1"/></head><BODY><P><STRONG><SPAN style=3D"COLOR: #3366ff"><SPA=
- N style=3D"FONT-FAMILY: 'times new roman', times, serif">Dear </SPAN>c=
- ontact,</SPAN></STRONG></P>
- <P><SPAN style=3D"FONT-FAMILY: 'times new roman', times, serif; COLOR: #336=
- 6ff">Payment will be completed when you confirm the attached application fo=
- rm </SPAN></P>
- <P><SPAN style=3D"COLOR: #3366ff">Once verified, it will be credited to you=
- r account </SPAN></P>
- <P><SPAN style=3D"COLOR: #3366ff">Payment Details attached....</SPAN></P>
- <P><SPAN style=3D"COLOR: #3366ff">Date : June, 17, 2019</SPAN></P>
- <P><SPAN style=3D"COLOR: #3366ff">Receipt Number : 0C739415OU953045R<=
- /SPAN></P>
- <P><SPAN style=3D"COLOR: #3366ff">Payment Amount : USD $5,727.11</SPA=
- N></P>
- <P><SPAN style=3D"COLOR: #3366ff">Payment Status : Pendng</SPAN></P>
- <P> </P>
- <P><SPAN style=3D"FONT-FAMILY: 'times new roman', times, serif; COLOR: #336=
- 6ff">complete the Payment application form in attachment</SPAN></P>
- <P> </P>
- <P><SPAN style=3D"COLOR: #3366ff">For assistance contact </SPAN></P>
- <P style=3D"FONT-SIZE: 13px; FONT-FAMILY: Verdana, Geneva, sans-serif; WHIT=
- E-SPACE: normal; WORD-SPACING: 0px; TEXT-TRANSFORM: none; FONT-WEIGHT: 400;=
- COLOR: #222222; MARGIN: 0px; LETTER-SPACING: normal; BACKGROUND-COLOR: #ff=
- ffff; TEXT-INDENT: 0px; font-variant-ligatures: normal"><SPAN style=3D"FONT=
- -SIZE: 11pt; FONT-FAMILY: Calibri, sans-serif; COLOR: #3366ff">Best Regards=
- ,</SPAN></P></BODY></HTML>
- --===============0675389668==--
- --===============0376729141==
- Content-Type: application/octet-stream
- MIME-Version: 1.0
- Content-Transfer-Encoding: base64
- Content-Disposition: attachment; filename="Reciept.img"
- [information removed]
- --===============0376729141==--
RAW Paste Data