Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- THREAT ATTRIBUTION: TA505
- SUBJECTS OBSERVED
- MONITORING REPORT
- SENDERS OBSERVED
- alcacuba@alcacuba.co.cu
- bookings@misselliestravel.co.uk
- chris@melificent.com
- gabriele.lippold@sys-team.de
- info@gurteknik.net
- jkim@yeonsung.ac.kr
- madalina.costache@evomag.ro
- soft@mtmprintsolutions.com
- vladislav.niedoba@cloverleaf.cz
- MALDOC FILE HASH
- None
- PAYLOAD FILE HASH
- None
- MALDOC LANDING PAGE URLS
- http://clb.bazzacco.net/k987m.html
- http://cukierniatylczynscy.lh.pl/y2afk.html
- http://deechtebol.com/h8c4ref.html
- http://kockens.pp.se/sgwrxo.html
- http://members.chello.nl/~d.jansen24/s3w2kdd.html
- http://mjlunalaw.com/t5f74.html
- http://reachtherapyllc.com/hxi0324.html
- http://texas-diesel.com/ahdht.html
- http://ts-shimada.com/zbycb.html
- bazzacco.net
- chello.nl
- deechtebol.com
- kockens.pp.se
- lh.pl
- mjlunalaw.com
- reachtherapyllc.com
- texas-diesel.com
- ts-shimada.com
- MALDOC DISTRIBUTION URLS
- https://filesharess.com/?d-297c5e5ae9ea4c5f
- filesharess.com
- TA505 C2s
- https://near-fast.com/wosl
- SUPPORTING EVIDENCE
- https://twitter.com/stoerchl/status/1298204662944980992
- https://app.any.run/tasks/ce2100b8-c4c5-4ac4-8d6c-2a20778e3c40/
Add Comment
Please, Sign In to add comment