Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- 2017-06-06 #jaff email phishing campaign "Order"
- Email sample:
- ------------------------------------------------------------------------------------------------------------
- From: "Lonnie sims" <Lonnie@dental-discount-plans-guide.com>
- To: [REDACTED]
- Subject: Order
- Date: Tue, 06 Jun 2017 15:14:35 +0600
- Attachment: MX-2310U_20170606_151435.pdf
- ------------------------------------------------------------------------------------------------------------
- - sender is random
- - subject is "Order"
- - email body is empty
- - attached file "MX-2310U_20170606_<6 digits>.pdf" contains embedded .docm file which contain macro that will download malware from one of the download sites:
- Download sites:
- http://10minutesto1.net/jt7677g6
- http://cafe-bg.com/jt7677g6
- http://cifroshop.net/jt7677g6
- http://community-gaming.de/jt7677g6
- http://cor-huizer.nl/jt7677g6
- http://essentialnulidtro.com/af/jt7677g6
- http://lcpinternational.fr/jt7677g6
- http://luxurious-ss.com/jt7677g6
- http://makh.ch/jt7677g6
- http://marcelrahner.com/jt7677g6
- http://mciverpei.ca/jt7677g6
- http://mitservices.net/jt7677g6
- http://myinti.com/jt7677g6
- http://mymobimarketing.com/jt7677g6
- http://oneby1.jp/jt7677g6
- http://rhiannonwrites.com/jt7677g6
- http://sdmqgg.com/jt7677g6
- http://seoulhome.net/jt7677g6
- http://sextoygay.be/jt7677g6
- http://siddhashrampatrika.com/jt7677g6
- http://squidincdirect.com.au/jt7677g6
- http://stlawyers.ca/jt7677g6
- http://studyonazar.com/jt7677g6
- http://supplementsandfitness.com/jt7677g6
- http://zechsal.pl/jt7677g6
- Malware:
- - encoded on download SHA256 eb5e237ba12a3179c7764a6137df4df314ba540ee6e7a96d6eff294f40b29a4b, MD5 76e150bceffaee4322fa70b2c48ced16
- - decode by XORing downloaded file with "ZID4uEPifSSuQCN32XMC7VOlV4Wu8BLn"
- - decoded SHA256 3377cbe4f2618e65f778d029e654a4cf07537c6cfb6b87c668ba2882d9bb4b44 ,MD5 5ca3d8cf1cde038e762b535ec4e905fe
- - VT: https://www.virustotal.com/file/3377cbe4f2618e65f778d029e654a4cf07537c6cfb6b87c668ba2882d9bb4b44/analysis/1496759309/
- - HA: https://www.reverse.it/sample/3377cbe4f2618e65f778d029e654a4cf07537c6cfb6b87c668ba2882d9bb4b44?environmentId=100
- C2:
- GET http://whoisfoxxrobiouy.net/a5/
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement