SHARE
TWEET

2017-09-19 Locky "HERBALIFE Order Number"

Racco42 Sep 19th, 2017 560 Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. 2017-09-19: #locky email phishing camapign "HERBALIFE Order Number: 6N0100NNNN"
  2.  
  3. Email sample:
  4. -------------------------------------------------------------------------------------------------------------
  5. From: "Herbalife" <svc_apacnts_2661@herbalife.com>
  6. To: [REDACTED]
  7. Date: Tue, 19 Sep 2017 17:42:27 +0700
  8. Subject: HERBALIFE Order Number: 6N01000673
  9.  
  10. Thank you for your order
  11.  
  12. Please find attached your tax invoice for 6N01000673
  13.  
  14. Your order is now being processed.
  15.  
  16. Attachment: 6N01000673_1.7z -> 6N01006808.vbs
  17. -------------------------------------------------------------------------------------------------------------
  18. - sender is: "Herbalife" <svc_apacnts_<1-4 digits>@herbalife.com>
  19. - subject is "HERBALIFE Order Number: 6N0100<4 digits>"
  20. - attached file "6N0100<4 digits>_1.7z" contains file "6N0100<4 digits>.vbs", a VBScript downloader
  21.  
  22. Download sites:
  23. http://arsmakina.org/JGHldb03m
  24. http://asiaresearchcenter.org/JGHldb03m
  25. http://bnphealthcare.com/JGHldb03m
  26. http://conxibit.com/JGHldb03m
  27. http://cxwebdesign.de/JGHldb03m
  28. http://diakoniestation-winnenden.de/JGHldb03m
  29. http://download.justowin.it/JGHldb03m
  30. http://ecofloraholland.nl/JGHldb03m
  31. http://felixsolis.mobi/JGHldb03m
  32. http://foodbikers.ch/JGHldb03m
  33. http://g-peer.at/JGHldb03m
  34. http://gui-design.de/JGHldb03m
  35. http://highpressurewelding.co.uk/JGHldb03m
  36. http://housecafe-essen.de/JGHldb03m
  37. http://isiquest1.com/JGHldb03m
  38. http://secureleads.com/JGHldb03m
  39. http://teracom.co.id/JGHldb03m
  40. http://ycgrp.jp/JGHldb03m
  41. http://zionbrand.su/p66/JGHldb03m
  42.  
  43. Malware:
  44. - locky, .yckol variant
  45. - SHA256: f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317, MD5: 43e9190f8f18e52dc361f775cc02b2ce
  46. - VT: https://www.virustotal.com/#/file/f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317/detection
  47. - HA: https://www.reverse.it/sample/f8e7dde2601ebeb7e30af4c54016223f1c42298176e1f2f5c4945ca6b8b88317?environmentId=100
RAW Paste Data
We use cookies for various purposes including analytics. By continuing to use Pastebin, you agree to our use of cookies as described in the Cookies Policy. OK, I Understand
Top