Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-08-01: #GlobeImposter email phishing camapign "Your order has been despatched"
- Samples: 570
- Email sample:
- ---------------------------------------------------------------------------------------------------------
- From: customer.service@lux-studio.co.uk
- To: [REDACTED]
- Subject: Your order has been despatched
- Date: Tue, 01 Aug 2017 14:37:08 +0530
- Dear Customer
- The attached document* provides details of items that have been packed and are ready for despatch.
- Please use your tracking number (contained within the attached document) to monitor the progress of your shipment.
- Customer Services (for customers in the UK mainland)
- Call: 03332 406406
- Email: cs@lux-studio.co.uk
- Opening Hours:
- Mon - Fri: 8am - 6pm
- Saturday: 9am - 5pm
- Export Sales (for customers outside UK mainland)
- Call: +44 1297 33666
- Email: exportsales@lux-studio.co.uk
- Opening Hours:
- Mon - Fri: 8am - 5.30pm (GMT)
- Kind regards
- Axminster Tools & Machinery
- Unit 10 Weycroft Avenue, Axminster EX13 5PH
- http://www.lux-studio.co.uk
- * In order to read or print the attached document, you will need to install Adobe Reader. You can download Adobe Reader free of charge by visiting http://www.adobe.com/
- products/acrobat/readstep2.html
- Attachment: LN8199906.zip -> LN1364887.js
- ---------------------------------------------------------------------------------------------------------
- - sender is customer.service@<domain>
- - subject is "Your order has been despatched"
- - attached file "LN<7 digits>.zip" contains file "LN<7 digits>.js" a JScritp downloader which downloads from:
- Download sites (URL contains suffix ??<random>=<random> which does not influence download):
- http://aimtravel.pl/94hg4g4g
- http://aitree.com/94hg4g4g
- http://bccapital.com/94hg4g4g
- http://dreamoneday.com/94hg4g4g
- http://edutechservices.in/94hg4g4g
- http://hanak-nafotil.kvalitne.cz/94hg4g4g
- http://inoveinternet.com.br/94hg4g4g
- http://kt-mm.com/94hg4g4g
- http://labettolasaigon.com/94hg4g4g
- http://lifestyleplumbing.com.au/94hg4g4g
- http://mybutterhalf.com/94hg4g4g
- http://petsplace.ca/94hg4g4g
- http://profileto.com/94hg4g4g
- http://samogonochka.net/94hg4g4g
- http://sethiwriting.com/94hg4g4g
- http://slvideo.net/94hg4g4g
- http://snehil.com/94hg4g4g
- http://stillsmokin.bravepages.com/94hg4g4g
- http://tbdexpress.com/94hg4g4g
- http://ttcpv.com/94hg4g4g
- http://urachart.com/94hg4g4g
- http://visitmymedia.com/94hg4g4g
- http://zubairfazal.com/94hg4g4g
- Malware:
- - SHA256 64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572, MD5 ece16814e892478cfb747662a49e6d9e
- - VT: https://www.virustotal.com/en/file/64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572/analysis/
- - HA: https://www.reverse.it/sample/64269fdc099cf6d45a29e26fd54ad4f78c1a91b58e4fb77a8247d47086f71572?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement