Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Date,Details,Email Payload Type,Users Targeted
- 12/2/2019,"""RE: DM119110143""; rtf -> agenttesla and formbook",Attachment,11
- 12/2/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,498
- 12/6/2019,"""BECC LTD RFQ 110419""; xlsx -> hawkeye",Attachment,2
- 12/6/2019,"""INQUIRY - TM/TC/ 2020-0059 / 2020-0098""; doc -> hawkeye",Attachment,2
- 12/9/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,881
- 12/9/2019,"All subjects contain ""Request to revise""; zip -> rtf -> avemaria",Attachment,3
- 12/9/2019,"""REMINDER: DHL Pending Notification/DHL_AWB_0011179303/AD""; img -> nanocore",Attachment,2
- 12/10/2019,"""Re: SOA- NET30""; img -> agenttesla",Attachment,83
- 12/10/2019,All subjects contain UPS; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,292
- 12/10/2019,All subjects contain 10.12.2019- or 11.12.2019-; link -> dridex,Link,26
- 12/12/2019,All subjects contain Apple; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,541
- 12/12/2019,"""REQUEST FOR QUOTATION NEEDED URGENTLY""; xlsx -> lokibot",Attachment,2
- 12/12/2019,"""PURCHASE ORDER FOR TOMORROW""; zip -> agenttesla",Attachment,2
- 12/15/2019,"""RE:PI( Invoice)""; xlsx -> lokibot",Attachment,2
- 12/15/2019,"All subjects contain ""Rent""; doc -> ostop -> trickbot continued to 12/17",Attachment,51
- 12/16/2019,"All attachments named ""invoice<digits>.doc""; doc -> predator ",Attachment,2
- 12/16/2019,"""RFQ- APPROVED PURCHASE ORDER POIM1911011""; docx -> doc -> formbook",Attachment,2
- 12/17/2019,"Various subjects, .top .online .site .xyz .club senders, app.php; link -> doc -> dridex continued to 12/19",Link,40
- 12/17/2019,"""Remittance Advice_44121719""; img -> link -> remcos rat",Attachment,3
- 12/17/2019,"""Signed Sales Contract 05 cont S18WP""; docx -> doc -> formbook",Attachment,2
- 12/17/2019,"""Re: TT copy""; doc -> lokibot continued to 12/19",Attachment,4
- 12/17/2019,"""Shipping Document""; img -> formbook",Attachment,3
- 12/17/2019,"""T/T $33,015.00""; rar -> formbook",Attachment,3
- 12/17/2019,"""Proforma Invoice""; rar -> agenttesla",Attachment,4
- 12/18/2019,All subjects contain Docusign; link -> hancitor -> pony -> evilpony -> cobaltstrike,Link,145
- 12/19/2019,All subjects contain Docusign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,154
- 12/19/2019,"""Transaction Receipt #0087""; img -> nanocore",Attachment,3
- 12/19/2019,"All attachments named ""parking17<digits>.doc""; doc -> predator ",Attachment,14
- 12/20/2019,All subjects contain ticket pkg_ attachments; doc -> predator,Attachment,4
- 12/20/2019,"""Overdue Invoice""; img -> asyncrat",Attachment,4
- 12/20/2019,"""Your flight ticket has been confirmed!""; iso -> agenttesla continued to 12/23",Attachment,5
- 12/20/2019,"""Your AWB Shipment has Arrived""; img -> remcos",Attachment,2
- 12/21/2019,"""po""; ace -> agenttesla",Attachment,2
- 12/21/2019,"""Payment Advice Ref: 4567TR: TT757""; iso -> agenttesla http",Attachment,4
- 12/23/2019,"All subjects contain ""fax""; doc -> trickbot",Attachment,23
- 12/24/2019,"All subjects contain ""holiday bonus""; link -> trickbot loader -> trickbot",Attachment,32
- 12/24/2020,"""payment confirmation""; img -> nanocore",Attachment,4
- 12/26/2020,"""Transaction Receipt""; img -> nanocore",Attachment,10
- 12/26/2020,"""Complaint on <user last name> at <company name>""; link -> trickbot",Link,12
- 12/25/2020,"""Re: <company name> corporate present""; link -> trickbot",Link,12
- c2's
- dec2/agenttesla-formbook/,us2.smtp.mailhostbox.com
- dec6/agenttesla/,smtp.strykeir.com
- dec6/agenttesla/2/,smtp.strykeir.com
- dec6/hawkeye/,mail.privateemail.com
- dec6/hawkeye/3/,mail.privateemail.com
- dec6/hawkeye/another/,mail.privateemail.com
- dec9/agenttesla/,smtp.strykeir.com
- dec9/agenttesla/2/,78.142.19.101
- dec9/agenttesla/3/,mail.cominf.ro
- dec9/agenttesla/5/,mail.hhsportsprotection.com
- dec9/avemaria/,141.255.164.13
- dec9/formbook/,sangkinmalesnyaginihah.com
- dec9/formbook/another/,http://www.proteinengineering.science
- dec9/nanocore/,79.134.225.89
- dec9/nanocore/another/,miraqueen.publicvm.com
- dec9/phoenix/,bhavnatutor.com
- dec10/agenttesla/,mail.newmedicacare.com
- dec10/agenttesla/2/,mail.privateemail.com
- dec12/agenttesla/,smtp.perfectgenerators.com
- dec12/agenttesla/2/,smtp.tkbill.biz
- dec12/agenttesla/3/,smtp.strykeir.com
- dec12/formbook/,http://www.fitath0me.com/dg/
- dec12/lokibot/,corpcougar.in/chigo/Panel/five/fre.php
- dec12/lokibot/another/,http://corpcougar.in/chigo/Panel/five/fre.php
- dec13/agenttelsa/,smtp.s0udal.com
- dec13/lokibot/,http://onlygoood.com/ae1/fre.php
- dec15/another/,kissmeifucan.ddns.net
- dec15/lokibot/,http://worldatdoor.in/mexiii/Panel/five/fre.php
- dec15/lokibot/another/,http://corpcougar.in/chigo/Panel/five/fre.php
- dec15/nanocore/,reverse.spamassasins.icu
- dec15/remcos/,reverse.spamassasins.icu
- dec16/predator/,checksme.info
- dec17/agenttesla/,SMTP.yandex.com
- dec17/agenttesla/2/,smtp.juili-tw.com
- dec17/agenttesla/3/,smtp.juili-tw.com
- dec17/dridex/,162.213.37.188
- dec17/formbook/,www.seovault.site
- dec17/formbook/3/,http://www.mademoda.com/d2d/
- dec17/lokibot/another/,http://elettroveneta-it.com/oge/fre.php
- dec17/nanocore/,reverse.spamassasins.icu
- dec17/nanocore/2/,79.134.225.104
- dec17/remcos/,top.multigamingjo.waw.pl
- dec18/agenttesla/,smtp.juili-tw.com
- dec18/agenttesla/2/,mail.hhsportsprotection.com
- dec18/agenttesla/3/,smtp.tkbill.biz
- dec18/nancore/,79.134.225.104
- dec18/nancore/another/,reverse.spamassasins.icu
- dec19/agenttesla/,smtp.yandex.com
- dec19/agenttesla/2/,us2.smtp.mailhostbox.com
- dec19/agenttesla/3/,smtp.perfectgenerators.com
- dec19/agenttesla/4/,78.142.19.101
- dec19/lokibot/,http://svmarketingindia.com/jjv/Panel/five/fre.php
- dec19/nanocore/,51.38.92.6
- dec19/nanocore/another/,79.134.225.104
- dec19/nanocore/yetanother/,79.134.225.104
- dec19/predator/,http://coinbase-promo.info/
- dec20/agenttesla/,mail.shreejitransport.com
- dec20/agenttesla/2/,us2.smtp.mailhostbox.com
- dec20/agenttesla/3/,smtp.zoho.com
- dec20/agenttesla/4/,mail.gandi.net
- dec20/lokibot/,http://svmarketingindia.com/jjv/Panel/five/fre.php
- dec20/nanocore/,menorte.ddns.net
- dec20/predator/,http://yoursmb.info/api/check.get
- dec20/remcos/,futy.ga
- dec20/remcos/another/,top.multigamingjo.waw.pl
- dec21/agenttesla/,http://www.svmarketingindia.com/elittte/origin/inc/a179ad1bf53a51.php
- dec22/agenttesla/,us2.smtp.mailhostbox.com
- dec23/agenttesla/,mail.privateemail.com
- dec23/predator/,http://testing0.site/api/check.get
- dec24/agenttesla/,smtp.juili-tw.com
- dec26/nanocore/,185.103.96.151
- dec28/agenttesla/,us2.smtp.mailhostbox.com
- dec30/nanocore/,indomie.publicvm.com
- agenttesla/hawkeye efil emails
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
Advertisement
Add Comment
Please, Sign In to add comment