Definitely contained ransomware - Locky ransomware... This domain hit my radar this week as well [https://twitter.com/malwrhunterteam/status/808752888063332352] :
Their emails contained this downloader script: https://www.virustotal.com/en/file/12c72ccf0b64bc1b288c80e3ba8eb18bc88967264ca3ad392992354be9b51eb9/analysis/1481658274/ With this locky payload: https://www.virustotal.com/en/file/5e396520da517174e5556e5b2c3b6e6ff25214c083e4458248f1be2e89967c65/analysis/1481658302/ Carl VanNixon Security Analyst Threat Research Team Level 3 Communications 1025 Eldorado Blvd Broomfield, CO 80021 p: 720-888-4467 e: [email protected] -----Original Message----- From: mailop [mailto:[email protected]] On Behalf Of Benoit Panizzon Sent: Thursday, December 15, 2016 6:41 AM To: [email protected] Subject: Re: [mailop] domaincop247.com service? Hi > Based on your report and on this, I strongly suspect that this is a > scam. Yes, it turned out to be scam. The website hosting the abuse reports probably contained malware. The hoster took it offline after complaints from other ISP about fraudulent abuse reports regarding their ressources. Strange that a scammer targets abuse desks. :-) PS: In the meantime we also received notices about overdue invoices for said domain, but that was easily recognizable as scam as we know where we register our domains. We were asked to download the invoices hosted within the same IP Range as those abuse reports. -BenoƮt Panizzon- -- I m p r o W a r e A G - Leiter Commerce Kunden ______________________________________________________ Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133 Pratteln Fax +41 61 826 93 01 Schweiz Web http://www.imp.ch ______________________________________________________ _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop _______________________________________________ mailop mailing list [email protected] https://chilli.nosignal.org/cgi-bin/mailman/listinfo/mailop
