Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Date,Details,Email Payload Type,Users Targeted
- 11/4/2018,"""MAERSK LINE BILL OF LANDING DOCUMENT/INVOICE|RE:Confirm Account details""; img -> agenttesla continued to 11/6",Attachment,167
- 11/4/2019,"""PRICE FORECAST INQUIRY""; gz -> netwire continued to 11/5",Attachment,21
- 11/4/2019,"""APPROVED PURCHASE ORDER PO05-9189 & PO06-9190 FOB JEBEL ALI""; rar -> formbook",Attachment,2
- 11/4/2019,"""Payment slip attached""; iso -> agenttesla",Attachment,3
- 11/5/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony,Link,"2,377"
- 11/5/2019,"""RE:Confirm Account details""; img -> agenttesla continued to 11/7",Attachment,460
- 11/5/2019,"All subjects contain ""DHL Documents; BL/CI;""; xls -> dridex",Attachment,47
- 11/6/2019,"""RFQ#BQ-SRN-B19-GZU-815 Supplies""; iso -> agenttesla http",Attachment,3
- 11/6/2019,All subects contain Harvest; docm -> icedid -> trickbot,Attachment,26
- 11/6/2019,"""Your package has been delivered""; zip -> vbs -> dridex",Attachment,23
- 11/7/2019,"All subjects contain ""has invited you to Resume.doc""; doc -> get2",Attachment,529
- 11/7/2019,"""FedEx Notification""; img -> agenttesla",Attachment,169
- 11/8/2019,"All subjects contain ""Re: annual bonus form for""; link -> trickbot",Link,2
- 11/8/2019,"All subjects contain ""contract.docx""; docx -> get2",Link,126
- 11/11/2019,"All subjects contain ""Microsoft OneDrive N""; zip -> dridex continued to 11/12",Attachment,125
- 11/11/2019,"""Your package has been delivered""; zip -> vbs -> dridex",Attachment,2
- 11/11/2019,"""INVOICE COPY // 000060364|subjects contain payment|invoice|DHL""; xls -> dridex d35259088.xls",Attachment,21
- 11/11/2019,"""ASTIR SA -FINAL ORDER""; rar iso -> hawkeye keylogger",Attachment,2
- 11/12/2019,"""Shipment Document BL,INV and packing list""; ace -> agenttesla",Attachment,2
- 11/12/2019,"""Final Order""; iso rar -> hawkeye keylogger",Attachment,2
- 11/12/2019,"""RE: FACTURA DE FLETE DHL""; rar zip -> lokibot",Attachment,2
- 11/12/2019,"""Purchase Order 12/11/2019""; zip -> agenttesla",Attachment,5
- 11/13/2019,Various highjacked subjects; zip -> ursnif Heritage_Partners_Group.zip,Attachment,3
- 11/13/2019,"""Re: NEW ORDER-P.O. 8576353""; img -> agenttesla",Attachment,24
- 11/13/2019,"""New Order""; rar -> link -> agenttesla",Attachment,16
- 11/13/2019,"""New Order # DLU1910-951-DW, 3X HSRO-4040-FF - FCA / SO 138696553""; zip -> lnk -> agenttesla",Attachment,40
- 11/13/2019,"""Your package has been delivered""; zip -> vbs -> dridex",Attachment,5
- 11/14/2019,"""Urgent Quotation - #026548""; 7z -> agenttesla",Attachment,6
- 11/14/2019,"""Re: Purchase Order No. ( PO-191115-02837)""; rar -> agenttesla",Attachment,2
- 11/14/2019,"""?? RFQ CEPH CRM:041510000249 / F34269 J1704K-03136""; rar -> agenttesla continued to 11/15",Attachment,12
- 11/15/2019,"""HR has invited you to dismissal order.xlsx""; link -> xls -> get2 -> sdbot",Link,35
- 11/16/2019,"""DHL Express Shipment Confirmation [AWB-6966188176]""; ace -> lokibot",Attachment,2
- 11/16/2019,"""Quotation from WAYMAH LIMITED - Waterproofing Roof""; rtf -> agenttelsa",Attachment,3
- 11/16/2019,All attachments are iqy; buran ransomware,Attachment,13
- 11/17/2019,"""**TOP URGENT** SOA""; rar -> agenttesla continued to 11/18",Attachment,2
- 11/18/2019,"""SAMPLE""; img -> agenttesla",Attachment,8
- 11/18/2019,Various subjects; one letter <digits>_.zip -> vbs -> dridex,Attachment,17
- 11/18/2019,Various subjects; fax_id<digits>.doc attachment -> predatorthethief,Attachment,3
- 11/18/2019,"""V235 ASD Statement""; rtf -> netwire",Attachment,2
- 11/18/2019,"""RFQ Work Order# W45394 Quote# I33613 Ref# 2019-SA-RO-013 2019-09-27 9-42-00 AM""; rar -> agenttesla continued to 11/19",Attachment,17
- 11/19/2019,Various subjects; <digits>_customer_inv_<digits>.xls|invoice_form|invoice_letter -> dridex continued to 11/20,Attachment,132
- 11/19/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,50
- 11/19/2019,"""RFQ: Sheet & Specification""; iso -> agenttesla",Attachment,2
- 11/19/2019,"""FIND THE ATTACHED""; link -> formbook",Link,15
- 11/20/2019,"Most subjects contain ""RE: Payout""; link -> trickbot",Link,11
- 11/20/2019,"All subjects contain ""Microsoft OneDrive N""; zip -> dridex continued to 11/12",Attachment,3
- 11/20/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif,Link,12
- 11/20/2019,"Various subjects, xlsx -> lokibot",Attachment,9
- 11/20/2019,"""HSBC�SWIFT�Advice�Against�Order#�Ref:[CD0061282]�//�Customer�Ref�//:[A0028218]""; ace -> formbook",Attachment,3
- 11/21/2019,"""Fw: Re: Re: Request for quotation (Very Urgent)""; zip -> broken :(",Attachment,30
- 11/21/2019,"""New Order 2020""; xlsx -> agenttesla",Attachment,5
- 11/21/2019,"All subjects contain ""Annual Bonus|Invoice status""; link -> trickbot",Link,19
- 11/21/2019,"""Purchase Sample""; img ->",Attachment,2
- 11/22/2019,"""Re: Kindly Review Payment!""; doc -> netwire",Attachment,2
- 11/22/2019,"""Fwd: Statement for "": link -> trickbot",Link,12
- 11/23/2019,"""Re: Urgent Booking Confirmation!""; doc -> netwire",Attachment,3
- 11/24/2019,"""Re: Request for the current statement""; rar -> ",Attachment,8
- 11/25/2019,"All subjects contain ""bonus report|RE: <username> statement""; link -> trickbot",Link,23
- 11/25/2019,"""Case Number: BODO-119748116845""; exe -> formbook",Attachment,4
- 11/25/2019,"""Your Customer Sent You Files via WeTransfer""; link -> ",Link,4
- 11/26/2019,"Various subjects attachment name ""copy-Inv. Doc|invoice_swift_date ""; xls -> dridex",Attachment,113
- 11/26/2019,"""You have received a new fax, document <digits>""; doc -> trickbot",Attachment,2
- 11/26/2019,"""Request For Quotation and drawings""; doc -> raccoon stealer",Attachment,4
- 11/26/2019,"""RE: [order confirmation]: PO NOVEMBER 2019""; doc -> agenttesla",Attachment,2
- 11/26/2019,"All subjects contain ""Microsoft OneDrive N""; zip -> dridex",Attachment,4
- 11/26/2019,"Various subjects containing ""fax"" efax_ attachments; doc -> trickbot",Attachment,4
- 11/26/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif -> cobaltstrike,Link,388
- 11/27/2019,"""Shipment Document BL,INV and packing list""; ace -> formbook",Attachment,5
- 11/27/2019,All subjects contain DocuSign; link -> hancitor -> pony -> evilpony -> ursnif,Link,300
- nov1/agenttesla/,us2.smtp.mailhostbox.com
- nov1/agenttesla/2/,smtp.lbhrne.com
- nov1/hawkeye/,mail.privateemail.com
- nov4/agenttesla/,mail.arkazo.com
- nov4/agenttesla/2/,mailhostbox.com
- nov4/agenttesla/3/,smtp.sitechukandlreland.com
- nov4/agenttesla/4/,us2.smtp.mailhostbox.com
- nov4/agenttesla/5/,us2.smtp.mailhostbox.com
- nov4/agenttesla/6/,us2.smtp.mailhostbox.com
- nov4/formbook/,www.wellmadecostumes.com
- nov4/formbook/another/,http://www.emmajcoombe.com/h320/
- nov4/hawkeye/,mail.privateemail.com
- nov4/nanocore/,79.134.225.76
- nov4/nanocore/another/,79.134.225.76
- nov4/nanocore/yetanother/,79.134.225.76
- nov4/netwire/,noapology.climatechangeawareness.uk
- nov5/agenttesla-blackrat/,mail.kingstoncomplex.com
- nov5/agenttesla/,mail.jayakartasoundexpert.com
- nov5/avemaria/,favour.ddnsgeek.com
- nov5/dridex/,https://masteronare.com/function.php?3b3988df-c05b-4fca-93cc-8f82af0e3d2b
- nov6/agenttesla/,us2.smtp.mailhostbox.com
- nov6/agenttesla/2/,https://webtoall.in/men/inc/c7afb5603b20fe.php
- nov6/agenttesla/3/,us2.smtp.mailhostbox.com
- nov6/agenttesla/4/,mail.belfama.com
- nov6/formbook/,www.ido-expo.com
- nov6/orion/,smtp.btconrnect.com
- nov11/agenttesla/,mail.jayakartasoundexpert.com
- nov11/agenttesla/2/,mail.vermak.com.tr
- nov11/dridex/,https://maxinato.com/email.php
- nov11/hawkeye/,mail.ancopottary.com
- nov11/hawkeye/3/,smtp.arabsecurify.net
- nov11/hawkeye/another/,smtp.arabsecurify.net
- nov11/nanocore/,79.134.225.104
- nov11/netwire/,noapology.duckdns.org
- nov12/agenttesla/,secure.emailsrvr.com
- nov12/agenttesla/2/,us2.smtp.mailhostbox.com
- nov12/agenttesla/3/,smtp.yandex.com
- nov12/agenttesla/4/,smtp.ionos.com
- nov12/agenttesla/5/,smtp.pbrend.com
- nov12/agenttesla/6/,vermak.com.tr
- nov12/agenttesla/7/,us2.smtp.mailhostbox.com
- nov12/formbook/,www.xosuno.com/h342/
- nov12/hawkeye/,mail.ancopottary.com
- nov12/lokibot/,37.120.146.13/68259/roks/fre.php
- nov13/agenttesla/,smtp.hostinger.com
- nov13/agenttesla/2/,mail.jayakartasoundexpert.com
- nov13/agenttesla/3/,smtp.pbrend.com
- nov13/agenttesla/6/,smtp.hotelmadridtorrevieja.com
- nov13/agenttesla/7/,smtp.hotelmadridtorrevieja.com
- nov13/agenttesla/8/,smtp.rishichemlcals.com
- nov13/agenttesla/9/,smtp.hostinger.com
- nov13/dridex/,https://45.137.151.151/
- nov13/icedid/,http://aginia.net/data3.php?7D8AAD5B7419DE99
- nov13/netwire/,noapology.duckdns.org
- nov14/agenttesla/,mail.ushaprime.com
- nov14/agenttesla/2/,us2.smtp.mailhostbox.com
- nov14/agenttesla/3/,smtp.pbrend.com
- nov14/agenttesla/4/,us2.smtp.mailhostbox.com
- nov14/agenttesla/5/,smtp.yandex.com
- nov14/agenttesla/6/,smtp.pbrend.com
- nov14/dridex/,https://45.137.151.151/
- nov14/hawkeye/,mail.ancopottary.com
- nov14/pony/,http://yehovahbuilders.com/MySQL/panelnew/gate.php
- nov14/remcos/2/,top.multigamingjo.waw.pl
- nov15/agenttesla/,smtp.zoho.com
- nov15/agenttesla/another/,premium78.web-hosting.com
- nov15/nanocore/,chimurenga.duckdns.org
- nov16/agenttesla/,mail.ushaprime.com
- nov16/lokibot/,http://dadatiles.com.au/pounds/fre.php
- nov16/lokibot/another/,http://37.187.207.221/web-content/css/Panel/five/fre.php
- nov17/agenttelsa/,us2.smtp.mailhostbox.com
- nov18/agenttesla/,showpromotionsonline.com
- nov18/hawkeye/,mail.privateemail.com
- nov18/lokibot/,http://pms-center.com/mb/Panel/fre.php
- nov18/nanocore/,46.183.222.66
- nov18/nanocore/another/,khurramchalingang.ddns.net
- nov18/netwire/,almeenamarine.ddns.net
- nov18/trickbot/,188.165.62.17
- nov19/agenttesla/2/,us2.smtp.mailhostbox.com
- nov19/agenttesla/3/,smtp.hotelmadridtorrevieja.com
- nov19/agenttesla/4/,smtp.juili-tw.com
- nov19/formbook/,www.nwsouthroad.com/cix/
- nov19/hawkeye/,mail.omanipackaging.com
- nov19/lokibot/,http://awba-groups.com/Broken/fre.php
- nov19/ta505/,https://microsoft-store-en.com/490183
- nov20/agenttesla/,mail.shreejitransport.com
- nov20/agenttesla/2/,smtp.ionos.com
- nov20/agenttesla/3/,smtp.juili-tw.com
- nov20/agenttesla/4/,mail.tawakalimpex.com
- nov20/agenttesla/5/,us2.smtp.mailhostbox.com
- nov20/formbook/,http://www.domferz.com/h342/
- nov20/formbook/another/,www.thankslotto.com
- nov20/formbook/yetanother/,http://www.domferz.com/h342/
- nov20/lokibot/,http://indextechno.com/cyber/tech/coded/fre.php
- nov20/lokibot/2/,http://kitchenraja.in/jay/Panel/five/fre.php
- nov20/nanocore/,79.134.225.104
- nov20/njrat-agenttesla/,103.139.45.248
- nov20/trickbot/,117.255.221.135
- nov21/agenttesla/,us2.smtp.mailhostbox.com
- nov21/agenttesla/2/,smtp.juili-tw.com
- nov21/agenttesla/3/,showpromotionsonline.com
- nov21/agenttesla/4/,mail.koohejisafety.com
- nov21/lokibot/,http://indextechno.com/cyber/tech/coded/fre.php
- nov21/lokibot/another/,http://awba-groups.com/Broken/fre.php
- nov21/remcos/,reverse.spamassasins.icu
- nov21/trickbot/,https://195.123.220.193/run6/
- nov22/agenttesla/,smtp.tetenel.com
- nov22/agenttesla/2/,smtp.hotelmadridtorrevieja.com
- nov22/amadey/,http://217.8.117.46/5vFgnRd4hdDbgS3H/index.php
- nov22/hawkeye/,mail.lnventcast.in
- nov22/netwire/,185.165.153.221
- nov23/netwire/,superserver100.hopto.org
- nov24/agenttesla/,smtp.highestgame.us
- nov24/lokibot/,http://villa-samnang.com/wpadmin/sever/wpincludes/files/fre.php
- nov24/phoenix/,mail.foodreview.world
- nov25/agenttelsa/,mail.hervitama.co.id
- nov25/agenttelsa/2/,server252.web-hosting.com
- nov25/agenttelsa/3/,smtp.universelcanning.com
- nov25/agenttelsa/4/,mail.arkazo.com
- nov25/agenttelsa/5/,smtp.tkbill.biz
- nov25/formbook/,www.italianato.com
- nov25/hawkeye/,mail.privateemail.com
- nov25/nanocore/,91.193.75.181
- nov25/trickbot/,https://181.112.157.42:449/run8
- nov26/agenttesla/,smtp.cnlembor.com
- nov26/azorult/,https://algo.empirehempmarket.com/index.php
- nov26/dridex/,124.156.35.183
- nov26/formbook/,http://www.wasserschaden-hero.com/ut/
- nov26/hawkeye/,mail.privateemail.com
- nov26/hawkeye/2/,mail.privateemail.com
- nov26/hawkeye/3/,mail.privateemail.com
- nov26/raccoon/,http://34.76.145.229/gate/log.php
- nov26/trickbot/,108.170.52.149
- nov27/formbook/,www.jscheide.com/s0s/
- RCPT TO:<bijo@lbhrne.com>
- RCPT TO:<chinaloggers@juili-tw.com>
- RCPT TO:<eliteexports@yandex.com>
- RCPT TO:<erik.smeyers@grraco.com>
- RCPT TO:<gm-fc@omanipackaging.com>
- RCPT TO:<img@kingstoncomplex.com>
- RCPT TO:<info@highestgame.us>
- RCPT TO:<info@hotelmadridtorrevieja.com>
- RCPT TO:<info@rishichemlcals.com>
- RCPT TO:<info@showpromotionsonline.com>
- RCPT TO:<info@tawakalimpex.com>
- RCPT TO:<loggers@sitechukandlreland.com>
- RCPT TO:<mpotyrala@pbrend.com>
- RCPT TO:<nicholas@btconrnect.com>
- RCPT TO:<payurprice@arabsecurify.net>
- RCPT TO:<purchase@ushaprime.com>
- RCPT TO:<sales@cnlembor.com>
- RCPT TO:<star-money@tetenel.com>
- RCPT TO:<thb@tbh-tw.com>
- RCPT TO:<voicemail@showpromotionsonline.com>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement