2016-07-12 - LOCKY MALSPAM - SUBJECT: FW:

NOTES:

ASSOCIATED FILES:

  • 2016-07-12-malspam-data.csv   (1,104 bytes)
  • Traffic-from-malspam-2016-07-12-1355-UTC.pcap   (174,188 bytes)
  • Traffic-from-malspam-2016-07-12-1356-UTC.pcap   (171,189 bytes)
  • Traffic-from-malspam-2016-07-12-1402-UTC.pcap   (162,357 bytes)
  • Traffic-from-malspam-2016-07-12-1408-UTC.pcap   (160,405 bytes)
  • emails/2016-07-12-1355-UTC.eml   (12,895 bytes)
  • emails/2016-07-12-1356-UTC.eml   (12,714 bytes)
  • emails/2016-07-12-1402-UTC.eml   (12,808 bytes)
  • emails/2016-07-12-1408-UTC.eml   (12,903 bytes)
  • attachments/alan_copies_315759.zip   (8,825 bytes)
  • attachments/gregory_forward_937188.zip   (8,850 bytes)
  • attachments/robert_copies_560364.zip   (8,708 bytes)
  • attachments/susan_copies_104906.zip   (8,782 bytes)
  • extracted-files/-SWIFT-1ec2-.js   (81,589 bytes)
  • extracted-files/-SWIFT-43f-.js   (80,760 bytes)
  • extracted-files/-SWIFT-883f-.js   (80,807 bytes)
  • extracted-files/-SWIFT-f48e-.js   (81,616 bytes)
  • artifacts-from-infected-hosts/3VkFo0ErNhs9.exe   (139,776 bytes)
  • artifacts-from-infected-hosts/OWVQ1Igf.exe   (139,776 bytes)
  • artifacts-from-infected-hosts/_HELP_instructions.bmp   (3,864,030 bytes)
  • artifacts-from-infected-hosts/_HELP_instructions.html   (9,345 bytes)
  • artifacts-from-infected-hosts/j4NxFPY45Bz3Q.exe   (139,776 bytes)
  • artifacts-from-infected-hosts/xmLXfRH8gYbB7.exe   (139,776 bytes)

EMAILS


Shown above:  Email data from the spreadsheet (part 1 of 2).

 


Shown above:  Email data from the spreadsheet (part 2 of 2).

 


Shown above:  Text of the emails.

 

TRAFFIC


Shown above:  Traffic generated from the first email.


Shown above:  Traffic generated from the second email.


Shown above:  Traffic generated from the third email.


Shown above:  Traffic generated from the 4th email.

 

ASSOCIATED DOMAINS:

 

DOMAINS FROM THE DECRYPT INSTRUCTIONS:

 

FILE HASHES

LOCKY SAMPLES FROM THE INFECTED HOSTS:

 

IMAGES


Shown above:  Infected Windows desktop from one of the emails.

 

FINAL NOTES

Once again, here is the archive with all the data:

ZIP files are password-protected with the standard password.  If you don't know it, look at the "about" page of this website.

Click here to return to the main page.