Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Date,Details,Email Payload Type,Users Targeted
- 10/3/2019,"All subjects contain ""DocuSign""; link -> doc -> hancitor -> pony -> evilpony -> ursnif",Link,189
- 10/4/2019,"""Payment Advice (SOA)""; rar -> agenttesla",Attachment,6
- 10/5/2019,"""QUOTATION""; rtf -> hawkeye keylogger",Attachment,2
- 10/6/2019,"""Transfer copy of USD 29,658.00""; rar -> agenttelsa",Attachment,3
- 10/6/2019,All subjects contain fax or efax; docm -> trickbot,Attachment,28
- 10/6/2019,"""RE: Re: Re: Re: Proforma Invoice""; rar -> agenttesla",Attachment,13
- 10/8/2019,All subjects contain Docusign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,151
- 10/8/2019,"""Pre-advice of payment to your account""; rar -> netwire",Attachment,6
- 10/9/2019,"""Here you go""; docx -> doc -> revenge rat",Attachment,20
- 10/9/2019,All subjects contain Docusign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,19
- 10/10/2019,All subjects contain Docusign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,540
- 10/10/2019,"""Remittance Advice: Bank of America Customer Advice -""; zip -> lnk -> ps1 -> remcos rat",Attachment,2
- 10/10/2019,"""????????????? - DHL-#AWB130501923096""; zip -> lokibot",Attachment,2
- 10/10/2019,"""Re: Inquiry for quotation""; doc -> pony loader continued to 10/13",Attachment,61
- 10/11/2019,Various hijacked subjects; zip -> ursnif,Attachment,5
- 10/14/2019,"""REQUEST FOR QUOTATION""; rar -> remcos",Attachment,7
- 10/14/2019,"""Our Ref. # 190 � 32018/03/18""; ",Attachment,2
- 10/14/2019,Various hijacked subjects; js -> remcos rat wshrat,Attachment,2
- 10/15/2019,"""Message could not be delivered""; zip -> mydoom (really�..)",Attachment,2
- 10/16/2019,"All subjects contain ""REVISED""; xlsx -> lokibot",Attachment,3
- 10/16/2019,"""Request For Quotation""; rar -> agenttesla",Attachment,12
- 10/16/2019,All subjects contain Package|DHL; link -> hancitor -> pony -> evilpony -> ursnif,Link,333
- 10/17/2019,"""RE: PO : RSs & NP872""; zip -> lokibot",Attachment,22
- 10/17/2019,All subjects contain eFax; link -> hancitor -> pony -> evilpony -> ursnif,Link,530
- 10/17/2019,"""Inquiry of 2x40FT HC Super Heavy""; doc -> lokibot",Attachment,2
- 10/17/2019,"""RE: 4500062058-T-BUOH(87%)-D/A 30days from B/L date - ????-2019.10.10""; rar -> lokibot",Attachment,44
- 10/17/2019,"""RFQ#SQ00014397T""; rar -> lokibot",Attachment,77
- 10/18/2019,"""Order Sample""; img -> agenttesla",Attachment,3
- 10/21/2019,All subjects contain Price|Rate; link -> hancitor -> pony -> evilpony,Link,270
- 10/21/2019,"""Your package has been delivered <digits>""; zip -> vbs -> dridex loader",Attachment,9
- 10/22/2019,"""Statement for month of SEPT, 2019""; iso -> hawkeye",Attachment,2
- 10/22/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif,Link,236
- 10/22/2019,"""Re: SV:PAYMENT""; rar -> formbook",Attachment,2
- 10/23/2019,"""Purchase Order : PO-0205/19""; iso -> hawkeye keylogger",Attachment,2
- 10/23/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> cobaltstrike,Link,1317
- 10/23/2019,"""Order Sample""; img -> agenttesla",Attachment,2
- 10/24/2019,"""Urgent New Order""; img -> agenttesla",Attachment,3
- 10/24/2019,"""RFQ- Purchase Order for Commodity King Traders llc- FOB Jebel Ali""; doc -> formbook",Attachment,2
- 10/24/2019,"""DHL - Your Shipment is Here""; img -> netwire",Attachment,4
- 10/24/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif,Link,1550
- 10/25/2019,All subjects hijacked; zip -> ursnif,Attachment,2
- 10/25/2019,"All subjects contain ""QUOTE|Quotation""; img ->",Attachment,4
- 10/25/2019,"""Shipping Document/ Invoice and Packing list""; zip -> agenttesla",Attachment,2
- 10/25/2019,"""Ref Quote""; img",Attachment,3
- 10/25/2019,"""Latest scans""; link -> xls -> get2 -> sdbbot",Attachment,51
- 10/25/2019,"""KTI TRADING COMPANY-Urgent Order""; iso and jar, hawkeye and adwind",Attachment,2
- 10/28/2019,"Subjects are blank or ""Sample Order""; iso -> agenttelsa",Attachment,4
- 10/28/2019,"""Sync.com - secure link notification""; link -> ta505 dropper",Link,166
- 10/28/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,"1,612"
- 10/28/2019,"All subjects contain ""Copy of your Maxim Invoice""; link -> ta505 dropper",Link,41
- 10/28/2019,"""Purchase Order Number 0062023389""; link -> zip",Link,2
- 10/29/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,"2,284"
- 10/29/2019,"""RE: [order confirmation]: ORDER OCTOBER 2019""; rtf -> agenttesla",Attachment,2
- 10/29/2019,"""Confirm quotation availability""; doc -> link -> agenttesla continued to 11/1",Attachment,40
- 10/29/2019,"""DHL NOTIFICATION: AWB Number:06785388011""; gz -> netwire continued to 10/31",Attachment,28
- 10/29/2019,"""Order Confirmation""; gz -> netwire continued to 10/31",Attachment,16
- 10/30/2019,"All subjects contain ""your corporate parcel status""; link -> trickbot",Link,3
- 10/30/2019,"""Re: PO1910057 - CATALITE""; zip -> njrat",Attachment,5
- 10/30/2019,"""QUOTATION FOR PURCHASE ORDER EQ-PO -SEPT-2891A""; doc -> remcos",Attachment,2
- 10/30/2019,"""Re: final PI""; zip -> formbook continued to 10/31",Attachment,25
- 10/30/2019,"Alls subjects contain ""??:"", rar iso -> agenttesla",Attachment,2
- 10/31/2019,"""Revised order! PO. 2019-04""; doc -> formbook",Attachment,6
- 10/31/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,"2,004"
- malware c2's
- oct1/agenttesla/,smtp.chezgroups.com
- oct1/agenttesla/another/,mail.varikasery.com
- oct1/hawkeye/,smtp.arabsecurify.net
- oct1/metamorfo/,http://u00e1zquez.webcindario.com/Colaborades/
- oct2/adwind/,addahost.ddns.net
- oct2/agent-tesla-http/,http://grindtreue.online/gem/inc/76c93758881110.php
- oct2/agenttesla/,mail.torishima-qa.com
- oct2/agenttesla/another/,smtp.chezgroups.com
- oct2/nanocore/,59108.duckdns.org
- oct3/agenttesla/,us2.smtp.mailhostbox.com
- oct3/agenttesla/another/,mail.lasultanaoualidia.com
- oct3/hawkeye/,smtp.arabsecurify.net
- oct3/lokibot/,http://corpcougar.com/gozie/Panel/five/fre.php
- oct4/agenttesla/,smtp.chezgroups.com
- oct4/predator-ursnif/,http://forrf0410.info/api/check.get
- oct6/another/,mail.privateemail.com
- oct6/hawkeye/,smtp.arabsecurify.net
- oct6/remcos/,robertmoore.hopto.org
- oct7/agenttesla/,smtp.chezgroups.com
- oct7/agenttesla/3/,server1.monovm.com
- oct7/agenttesla/another/,us2.smtp.mailhostbox.com
- oct8/agenttesla/,mail.shivanilocks.com
- oct9/netwire/,trippleboss.warzonedns.com
- oct10/adwind-hawkeye/,lexd.duckdns.org
- oct10/agenttesla/,mail.deepblueamerica.com
- oct10/agenttesla/2/,mail.privateemail.com
- oct10/lokibot/,nonomonojolipoiubtrewert.tk/fre.php
- oct10/nanocore/,godwin.ddns.net
- oct10/pony/,onlygoodm.com
- oct10/remcos/,sub.winkcaffe.waw.pl
- oct11/azorult/,adityebirla.com/kent/index.php
- oct13/adwind/,respainc.duckdns.org
- oct13/agenttesla/,mail.gandi.net
- oct13/pony-loader/,www.jicago-jp.com/eng/gate.php
- oct14/agenttesla/,mail.privateemail.com
- oct14/agenttesla/2/,us2.smtp.mailhostbox.com
- oct14/agenttesla/3/,mail.privateemail.com
- oct14/azorult/,corpcougar.com
- oct14/dridex/,185.14.148.34
- oct14/nanocore/,213.152.162.170
- oct14/nanocore/another/,sub.thebest1jewels.waw.pl
- oct14/predator/,www.serawledindustries.com
- oct14/remcos-wshrat/,http://79.134.225.95:4050/is-ready
- oct14/remcos/,sub.thebest1jewels.waw.pl
- oct15/agenttesla/,mail.privateemail.com
- oct15/agenttesla/2/,us2.smtp.mailhostbox.com
- oct15/hawkeye/,smtp.universelcanning.com
- oct15/lokibot/,http://corpcougar.com/gozie/Panel/five/fre.php
- oct16/agenttesla/,smtp.yandex.com
- oct16/agenttesla/2/,mail.alserhgroup.com
- oct16/agenttesla/3/,us2.smtp.mailhostbox.com
- oct16/agenttesla/4/,us2.smtp.mailhostbox.com
- oct16/agenttesla/5/,mail.sysmarkbd.com
- oct16/dridex/,https://185.14.148.34/
- oct16/formbook/,www.chuangshunchem.com/um/
- oct16/hawkeye/,mail.privateemail.com
- oct16/hawkeye/2/,smtp.universelcanning.com
- oct16/lokibot/,http://tahetah.ir/.lox/fre.php
- oct16/nanocore/,godwin.ddns.net
- oct17/agenttesla/,us2.smtp.mailhostbox.com
- oct17/agenttesla/2/,us2.smtp.mailhostbox.com
- oct17/agenttesla/4/,smtp.rishichemlcals.com
- oct17/hawkeye/,smtp.arabsecurify.net
- oct17/lokibot/,atritei.icu/68259/roks/fre.php
- oct17/lokibot/3/,http://modatie.gq/68259/roks/fre.php
- oct18/agenttesla/,my103.ht2u.net
- oct18/agenttesla/another/,smtp.btconrnect.com
- oct20/,https://baloobafoudanitojahdge.space/n/file.php
- oct21/adwind-hawkeye/,lexd.duckdns.org
- oct21/agenttesla/,us2.smtp.mailhostbox.com
- oct21/dridex/,185.14.148.34
- oct21/formbook/,http://www.moraxy.com/dg/
- oct21/lokibot/,http://jajar.ru/kris/Panel/fre.php
- oct21/ostap/,185.130.104.187
- oct21/wshrat/,homi.doomdns.org
- oct22/agenttesla/,us2.smtp.mailhostbox.com
- oct22/agenttesla/2/,mail.shivanilocks.com
- oct22/agenttesla/3/,mail.varikasery.com
- oct22/avemaria/,185.165.153.46
- oct22/formbook/,www.mizorl.com/s40/
- oct22/hawkeye/,smtp.arabsecurify.net
- oct22/remcos/,top.subaroone.waw.pl
- oct23/agenttesla/2/,smtp.sitechukandlreland.com
- oct23/agenttesla/3/,server1.monovm.com
- oct23/hawkeye/,smtp.arabsecurify.net
- oct23/hawkeye/2/,mail.privateemail.com
- oct23/orion/,smtp.btconrnect.com
- oct23/pony/,http://chinalarnpbase.com/chief/gate.php
- oct24/agenttelsa-lokibot/,http://dadatiles.com.au/cba/Panel/five/fre.php
- oct24/agenttesla/,smtp.it8-e.org
- oct24/emotet/,http://201.213.32.59/devices/raster/
- oct24/formbook/,http://www.cancertreatmenttransport.com/dg/
- oct24/hawkeye/,grindtreue.online
- oct24/lokibot/,http://gracetime.tech/cyber/tech/coded/fre.php
- oct24/netwire/,fartgul.duckdns.org
- oct25/agenttesla/,smtp.sitechukandlreland.com
- oct25/agenttesla/2/,mail.hervitama.co.id
- oct25/agenttesla/3/,mail.coducation.com.my
- oct25/hawkeye-adwind/,mail.sigmachennai.com
- oct27/agenttesla/,mail.dsectioncreative.com
- oct27/formbook/,http://www.hairminders.com/px/
- oct27/hawkeye/,mail.privateemail.com
- oct28/agenttesla/,mailhostbox.com
- oct28/agenttesla/2/,lh2.monovm.com
- oct28/avemaria/,185.165.153.46
- oct28/avemaria/another/,favour.ddnsgeek.com
- oct28/formbook/,http://www.rwinzresearch.com/um/
- oct28/hawkeye/,smtp.spencneco.com
- oct28/netwire/,185.165.153.221
- oct28/remcos/,samuelcity.ddns.net
- oct28/ta505/,office-en-service.com
- oct29/agenttesla/,smtp.vwestrock.com
- oct29/agenttesla/3/,mail.wepmill.website
- oct29/avemaria-remcos/,mnx.duckdns.org
- oct29/netwire/,cowboyz.climatechangeawareness.uk
- oct30/agenttesla/,us2.smtp.mailhostbox.com
- oct30/agenttesla/2/,mail.hervitama.co.id
- oct30/agenttesla/3/,smtp.bmssrevis.com
- oct30/agenttesla/4/,smtp.yandex.com
- oct30/azorult/,https://adityebirla.com/kent/index.php
- oct30/formbook/,http://www.kovaxy.com/b5/
- oct30/njrat/,213.208.152.215
- oct30/raccoon/,http://34.65.76.39/gate/log.php
- oct30/remcos/,sub.thebest1jewels.waw.pl
- oct30/trickbot/,https://192.3.104.46/trgt98888
- oct31/adwind/,0000rrrvvv.duckdns.org
- oct31/agenttesla/,smtp.btconrnect.com
- oct31/agenttesla/3/,mail.hervitama.co.id
- oct31/agenttesla/4/,smtp.lbhrne.com
- oct31/agenttesla/5/,mail.kingstoncomplex.com
- oct31/formbook/,http://www.golaminators.com/bo/
- oct31/formbook/another/,http://www.garthhassel.com/px/
- oct31/nancore/,185.217.1.137
- agenttesla/hawkeye exfil email addresses
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
- RCPT TO:<[email protected]>
Advertisement
Add Comment
Please, Sign In to add comment