malwageddon

Malwageddon's Pastebin

1,639 16,816 0 10 years ago
Name / Title Added Expires Hits Comments Syntax  
IOC - cloudmade.com - 2015-09-22 Sep 22nd, 2015 Never 151 0 HTML -
Partially decoded attachment - 2015-09-16 Sep 16th, 2015 Never 661 0 HTML -
IOC - www.projectrace.com - 2015-09-07 Sep 7th, 2015 Never 245 0 HTML -
pDNS domain names on Hacking Team IPs Jul 6th, 2015 Never 489 0 None -
Neutrino EK landing page sample - Mar 2015 Mar 20th, 2015 Never 684 0 HTML -
Neutrino EK landing page sample - Dec 2014 Mar 20th, 2015 Never 845 0 HTML -
IOC - capovelo.com - 2014-12-18 Dec 18th, 2014 Never 434 0 JavaScript -
IOC - ads.financialcontent.com - 2014-12-16 Dec 16th, 2014 Never 327 0 JavaScript -
Config file extracts from a recent DYRE sample - 2014-10-15 Oct 17th, 2014 Never 800 0 None -
IOC - ads.financialcontent.com - 2014-10-15 Oct 16th, 2014 Never 412 0 JavaScript -
Nuclear EK deobfuscated landing page - 2014-09-12 Sep 23rd, 2014 Never 641 0 JavaScript -
Nuclear EK landing page example - 2014-09-12 Sep 22nd, 2014 Never 899 0 JavaScript -
SweetOrange EK deobfuscated landing page - 2014-09-16 Sep 18th, 2014 Never 653 0 JavaScript -
SweetOrange EK landing page example - 2014-09-16 Sep 17th, 2014 Never 670 0 JavaScript -
IOC - www.coffeeandquinoa.com - 2014-09-10 Sep 10th, 2014 Never 282 0 HTML -
IOC - www.goldseek.com 2014-08-28 Aug 29th, 2014 Never 332 0 JavaScript -
IOC earthsky.org - 2014-08-27 Aug 27th, 2014 Never 255 0 JavaScript -
IOC - englishrussia.com Aug 25th, 2014 Never 277 0 JavaScript -
IOC - www.thecitywire.com Aug 13th, 2014 Never 298 0 JavaScript -
ibmtvdemo.edgesuite.net suspicious JS request Aug 7th, 2014 Never 273 0 HTML -
List of websites redirecting to Fiesta EK - 2014-07-24 Jul 24th, 2014 Never 444 0 None -
SweetOrange EK redirect chain example - 2014-06/07 Jul 3rd, 2014 Never 347 0 JavaScript -
Suspicious redirect - ibmtvdemo.edgesuite.net Jul 3rd, 2014 Never 488 0 HTML -
IOC - www.askmen.com Jun 25th, 2014 Never 327 0 JavaScript -
IOC - legacy.americanpayroll.org Jun 24th, 2014 Never 252 0 HTML -
IOC - www.homebusinessmag.com dishes out malicious JS Jun 23rd, 2014 Never 224 0 JavaScript -
Suspicious - www.foxitsoftware.com JS script Jun 23rd, 2014 Never 279 0 HTML -
IOC - www.bankofbotswana.bw website leading to Magnitude EK Jun 9th, 2014 Never 455 0 JavaScript -
Malware email campaign with .gadget files attachments May 19th, 2014 Never 347 0 None -
Proof of Compromise / www.footballfoundation.org May 9th, 2014 Never 197 0 None -
UnrecomServer jRAT - sample by @zertox1 Apr 28th, 2014 Never 342 0 XML -
Unknown EK(listentobitcoin.com) - 2014-01-14 Jan 14th, 2014 Never 248 0 None -
Unknown EK URL pattern - 2013-11-22 Nov 23rd, 2013 Never 411 0 None -
LinkedIn SPAM campaign 2013-09-30 Sep 30th, 2013 Never 133 0 None -
Unknown EK / IE7 Exploit Sep 28th, 2013 Never 513 0 JavaScript -
FAX phishing email campaign Jul 18th, 2013 Never 141 0 None -
VISA phishing email campaign Jul 17th, 2013 Never 330 0 None -
ADP themed phishing Jul 15th, 2013 Never 141 0 None -
HSBC themed phishing Jul 15th, 2013 Never 422 0 None -
Xpiro.D domain names Jul 15th, 2013 Never 446 0 None -
"TAX Appeal Declinde" SPAM wave Jul 12th, 2013 Never 120 0 None -
WU SPAM wave Jul 11th, 2013 Never 98 0 None -
'Styxy' Cool EK pattern Jul 9th, 2013 Never 103 0 None -
Nuclear EK pattern seen on 2013-06-25 Jun 26th, 2013 Never 89 0 None -
Goofware pattern seen on 2013-06-21 Jun 21st, 2013 Never 75 0 None -
Sweet Orange EK pattern seen on 2013-06-18 Jun 19th, 2013 Never 103 0 None -
Flimkit pattern seen on 2013-06-17 Jun 18th, 2013 Never 114 0 None -