Advertisement
Racco42

2017-09-19 Locky "HERBALIFE Order Number"

Sep 19th, 2017
2,967
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.89 KB | None | 0 0
  1. 2017-09-19: #locky email phishing camapign "HERBALIFE Order Number: 6N0100NNNN"
  2.  
  3. Email sample:
  4. -------------------------------------------------------------------------------------------------------------
  5. From: "Herbalife" <svc_apacnts_2661@herbalife.com>
  6. To: [REDACTED]
  7. Date: Tue, 19 Sep 2017 17:42:27 +0700
  8. Subject: HERBALIFE Order Number: 6N01000673
  9.  
  10. Thank you for your order
  11.  
  12. Please find attached your tax invoice for 6N01000673
  13.  
  14. Your order is now being processed.
  15.  
  16. Attachment: 6N01000673_1.7z -> 6N01006808.vbs
  17. -------------------------------------------------------------------------------------------------------------
  18. - sender is: "Herbalife" <svc_apacnts_<1-4 digits>@herbalife.com>
  19. - subject is "HERBALIFE Order Number: 6N0100<4 digits>"
  20. - attached file "6N0100<4 digits>_1.7z" contains file "6N0100<4 digits>.vbs", a VBScript downloader
  21.  
  22. Download sites:
  23. http://arsmakina.org/JGHldb03m
  24. http://asiaresearchcenter.org/JGHldb03m
  25. http://bnphealthcare.com/JGHldb03m
  26. http://conxibit.com/JGHldb03m
  27. http://cxwebdesign.de/JGHldb03m
  28. http://diakoniestation-winnenden.de/JGHldb03m
  29. http://download.justowin.it/JGHldb03m
  30. http://ecofloraholland.nl/JGHldb03m
  31. http://felixsolis.mobi/JGHldb03m
  32. http://foodbikers.ch/JGHldb03m
  33. http://g-peer.at/JGHldb03m
  34. http://gui-design.de/JGHldb03m
  35. http://highpressurewelding.co.uk/JGHldb03m
  36. http://housecafe-essen.de/JGHldb03m
  37. http://isiquest1.com/JGHldb03m
  38. http://secureleads.com/JGHldb03m
  39. http://teracom.co.id/JGHldb03m
  40. http://ycgrp.jp/JGHldb03m
  41. http://zionbrand.su/p66/JGHldb03m
  42.  
  43. Malware:
  44. - locky, .yckol variant
  45. - SHA256: f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317, MD5: 43e9190f8f18e52dc361f775cc02b2ce
  46. - VT: https://www.virustotal.com/#/file/f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317/detection
  47. - HA: https://www.reverse.it/sample/f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317?environmentId=100
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement