2016-05-19 - LOCKY MALSPAM - FAKE HP SCANJET MESSAGES
ASSOCIATED FILES:
- ZIP archive with all the info: 2016-05-19-Locky-malspam-data.zip 951.0 kB (950,997 bytes)
NOTES:
- The Palo Alto Networks Unit 42 blog about Locky ransomware can be found here.
- Proofpoint's blog about Locky ransomware is available here.
- Another post covering this same wave of Locky malicious spam (malspam) from today:
EMAILS AND ATTACHMENTS
Shown above: Data from the .csv spreadsheet on 4 emails from today's Locky malspam.
Shown above: Data from the .csv spreadsheet on 4 attachments from today's Locky malspam.
Shown above: Example from one of the emails.
TRAFFIC
Shown above: Traffic from enabling macros on the .docm files, filtered in Wireshark.
HTTP REQUESTS FROM THE WORD MACROS:
- 91.223.216.67 port 80 - zarabotat.yomu.ru - GET /grh5444tg
- 93.185.104.29 port 80 - ernetfree.net - GET /grh5444tg
- 213.189.197.201 port 80 - darts-pr.ru - GET /grh5444tg
POST-INFECTION CALLBACK FROM THE LOCKY SAMPLE:
- 92.63.87.48 port 80 - 92.63.87.48 - POST /userinfo.php
IMAGES
Shown above: Desktop of a Windows host after enabling macros on one of the .docm files from the malspam.
ZIP ARCHIVE CONTENTS
- 2016-05-19-Locky-malspam-traffic.pcap (431,177 bytes)
- 2016-05-19-Locky-malspam-info.csv (897 bytes)
- artifacts-from-infected-host/2016-05-19-Locky-sample.exe (221,184 bytes)
- artifacts-from-infected-host/2016-05-19-Locky_HELP_instructions.bmp (3,721,466 bytes)
- artifacts-from-infected-host/2016-05-19-Locky_HELP_instructions.html (9,749 bytes)
- attachments/MSG00002381373.docm (57,158 bytes)
- attachments/MSG000244771637272.docm (57,221 bytes)
- attachments/MSG000719948919814.docm (57,148 bytes)
- attachments/MSG0008077856.docm (57,243 bytes)
- emails/2016-05-19-1215-UTC.eml (78,831 bytes)
- emails/2016-05-19-1320-UTC.eml (78,7211 bytes)
- emails/2016-05-19-1411-UTC.eml (78,719 bytes)
- emails/2016-05-19-1440-UTC.eml (78,823 bytes)
FINAL NOTES
Once again, here is the associated file:
- ZIP archive with all the info: 2016-05-19-Locky-malspam-data.zip 951.0 kB (950,997 bytes)
The ZIP file is password-protected with the standard password. If you don't know it, look at the "about" page of this website.
Click here to return to the main page.