Racco42

2017-08-01 GlobeImposter "Your order has been despatched"

Aug 1st, 2017
2,102
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.75 KB | None | 0 0
  1. 2017-08-01: #GlobeImposter email phishing camapign "Your order has been despatched"
  2. Samples: 570
  3.  
  4. Email sample:
  5. ---------------------------------------------------------------------------------------------------------
  6. To: [REDACTED]
  7. Subject: Your order has been despatched
  8. Date: Tue, 01 Aug 2017 14:37:08 +0530
  9. Dear Customer
  10.  
  11. The attached document* provides details of items that have been packed and are ready for despatch.
  12.  
  13. Please use your tracking number (contained within the attached document) to monitor the progress of your shipment.
  14.  
  15. Customer Services (for customers in the UK mainland)
  16. Call: 03332 406406
  17.  
  18. Opening Hours:
  19. Mon - Fri: 8am - 6pm
  20. Saturday: 9am - 5pm
  21.  
  22. Export Sales (for customers outside UK mainland)
  23. Call: +44 1297 33666
  24.  
  25. Opening Hours:
  26. Mon - Fri: 8am - 5.30pm (GMT)
  27.  
  28. Kind regards
  29.  
  30. Axminster Tools & Machinery
  31. Unit 10 Weycroft Avenue, Axminster EX13 5PH
  32. http://www.lux-studio.co.uk
  33.  
  34. * In order to read or print the attached document, you will need to install Adobe Reader. You can download Adobe Reader free of charge by visiting http://www.adobe.com/
  35. products/acrobat/readstep2.html
  36.  
  37. Attachment: LN8199906.zip -> LN1364887.js
  38. ---------------------------------------------------------------------------------------------------------
  39. - sender is customer.service@<domain>
  40. - subject is "Your order has been despatched"
  41. - attached file "LN<7 digits>.zip" contains file "LN<7 digits>.js" a JScritp downloader which downloads from:
  42.  
  43. Download sites (URL contains suffix ??<random>=<random> which does not influence download):
  44. http://aimtravel.pl/94hg4g4g
  45. http://aitree.com/94hg4g4g
  46. http://bccapital.com/94hg4g4g
  47. http://dreamoneday.com/94hg4g4g
  48. http://edutechservices.in/94hg4g4g
  49. http://hanak-nafotil.kvalitne.cz/94hg4g4g
  50. http://inoveinternet.com.br/94hg4g4g
  51. http://kt-mm.com/94hg4g4g
  52. http://labettolasaigon.com/94hg4g4g
  53. http://lifestyleplumbing.com.au/94hg4g4g
  54. http://mybutterhalf.com/94hg4g4g
  55. http://petsplace.ca/94hg4g4g
  56. http://profileto.com/94hg4g4g
  57. http://samogonochka.net/94hg4g4g
  58. http://sethiwriting.com/94hg4g4g
  59. http://slvideo.net/94hg4g4g
  60. http://snehil.com/94hg4g4g
  61. http://stillsmokin.bravepages.com/94hg4g4g
  62. http://tbdexpress.com/94hg4g4g
  63. http://ttcpv.com/94hg4g4g
  64. http://urachart.com/94hg4g4g
  65. http://visitmymedia.com/94hg4g4g
  66. http://zubairfazal.com/94hg4g4g
  67.  
  68. Malware:
  69. - SHA256 64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572, MD5 ece16814e892478cfb747662a49e6d9e
  70. - VT: https://www.virustotal.com/en/file/64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572/analysis/
  71. - HA: https://www.reverse.it/sample/64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment