malware_traffic

Malware_traffic's Pastebin

128,377 557,053 6 years ago
Name / Title Added Expires Hits Syntax  
2020-12-09 (Wednesday) - TA551 (Shathak) Word docs... Dec 9th, 2020 Never 2,495 None -
2020-12-07 (Monday) - TA551 (Shathak) Word docs wi... Dec 7th, 2020 Never 2,387 None -
2020-12-02 (Wednesday) through 2020-12-03 (Thursda... Dec 4th, 2020 Never 3,375 None -
2020-11-30 (Monday) TA551 (Shathak) Word docs with... Nov 30th, 2020 Never 2,498 None -
2020-11-25 (Wednesday) TA551 (Shathak) Word docs w... Nov 25th, 2020 Never 1,476 None -
2020-11-24 (Tuesday) - TA551 (Shathak) Word docs w... Nov 24th, 2020 Never 2,497 None -
2020-11-23 (Monday) - ZLoader infection with follo... Nov 23rd, 2020 Never 2,280 None -
2020-11-16 - Fake FedEx email Nov 16th, 2020 Never 1,994 None -
2020-11-11 (Wednesday) - IcedID from myResume.xlsb Nov 11th, 2020 Never 3,207 None -
2020-11-11 (Wed) - Qakbot-style spreadsheets with... Nov 11th, 2020 Never 2,576 None -
Attachment passwords from TA551 (Shathak) malspam Nov 10th, 2020 Never 1,750 None -
2020-11-06 (Friday) - malspam pushing Formbook Nov 6th, 2020 Never 1,546 None -
2020-11-05 (Thursday) - TA551 (Shathak) Japanese-t... Nov 4th, 2020 Never 2,256 None -
2020-11-04 (Wednesday) - TA551 (Shathak) Japanese-... Nov 4th, 2020 Never 2,082 None -
2020-11-03 (Tuesday) - TA551 (Shathak) Japanese-te... Nov 3rd, 2020 Never 1,491 None -
2020-10-29 (Thursday) - TA551 (Shathak) Japanese l... Oct 29th, 2020 Never 2,011 None -
2020-10-28 (Wednesday) - TA551 (Shathak) Japanese... Oct 29th, 2020 Never 1,994 None -
2020-10-27 (Tuesday) - TA551 (Shathak) Japanese-la... Oct 27th, 2020 Never 2,275 None -
2020-10-27 (Tuesday) - Hancitor with Cobalt Strike... Oct 27th, 2020 Never 3,391 None -
2020-10-20 (Tuesday) - TA551 (shathak) Word docs p... Oct 21st, 2020 Never 1,731 None -
2020-10-15 (Thursday) - BazaLoader from Google Doc... Oct 15th, 2020 Never 2,313 None -
2020-10-14 (Wednesday) - TA551 (Shathak) Word docs... Oct 14th, 2020 Never 2,332 None -
2020-10-14 (Wednesday) - Emotet malspam example Oct 14th, 2020 Never 1,954 None -
2020-10-07 (Wednesday) - TA551 (shathak) Word docs... Oct 7th, 2020 Never 2,379 None -
2020-10-07 (Wednesday) - Malspam with XLSX attachm... Oct 7th, 2020 Never 2,410 None -
2020-10-05 (Monday) - Qakbot (Qbot) abc013 Oct 5th, 2020 Never 2,539 None -
2020-10-05 (Monday) DHL-themed malspam pushes Drid... Oct 5th, 2020 Never 2,393 None -
2020-09-30 - Qakbot malspam example Sep 30th, 2020 Never 2,239 None -
2020-09-23 (Wednesday) TA551 (Shathak) Word docs p... Sep 23rd, 2020 Never 2,253 None -
2020-09-21 (Monday) TA551 (Shathak) Word docs push... Sep 21st, 2020 Never 2,033 None -
2020-09-17 (Thursday) TA551 (Shathak) Word docs pu... Sep 17th, 2020 Never 3,092 None -
2020-09-16 (Wednesday) TA551 (Shathak) Word docs p... Sep 16th, 2020 Never 2,858 None -
2020-09-15 - BazarLoader malware from Google Docs... Sep 15th, 2020 Never 2,865 None -
2020-09-11 (Friday) - myResume.xls pushes ZLoader... Sep 11th, 2020 Never 2,468 None -
2020-09-11 (Friday) TA551 (Shathak) Word docs push... Sep 11th, 2020 Never 2,333 None -
2020-09-10 (Thursday) TA551 (Shathak) Word docs pu... Sep 10th, 2020 Never 2,442 None -
2020-09-08 (Tuesday) TA551 (Shathak) Word docs pus... Sep 8th, 2020 Never 2,460 None -
2020-08-20 - Notes on recent TA551 (shathak) activ... Aug 20th, 2020 Never 2,321 None -
2020-08-20 (Thursday) - TA551 (Shathak) word docs... Aug 20th, 2020 Never 2,973 None -
2020-08-18 (Tuesday) - Emotet malspam example Aug 18th, 2020 Never 1,223 None -
2020-08-17 (Monday) - TA551 (shathak) Word docs wi... Aug 17th, 2020 Never 3,692 None -
2020-08-11 (Tuesday) - TA551 (shathak) Word docs w... Aug 11th, 2020 Never 4,195 None -
2020-08-10 (Monday) TA551 (shathak) Word docs with... Aug 10th, 2020 Never 5,559 None -
2020-08-05 - "Campaign 56" on amazonaws Aug 5th, 2020 Never 7,888 None -
2020-08-03 (Monday) - Qakbot (Qbot) spx147 Aug 3rd, 2020 Never 12,298 None -
2020-07-30 (Thursday) - TA551 (Shathak) Word docs... Jul 30th, 2020 Never 10,206 None -
2020-07-28 - Password-protected XLS pushes ZLoader Jul 28th, 2020 Never 8,320 None -
2020-07-28 (Tuesday) - TA551 word docs pushing Ice... Jul 28th, 2020 Never 9,698 None -
2020-07-27 (Monday) - TA551 Word docs push IcedID... Jul 27th, 2020 Never 9,165 None -
2020-07-24 (Friday) TA551 word docs with macros fo... Jul 24th, 2020 Never 13,154 None -
2020-07-23 (Thursday) - TA551 word docs with macro... Jul 23rd, 2020 Never 14,264 None -
2020-07-22 (Wed) - Password-protected XLS files pu... Jul 22nd, 2020 Never 7,726 None -
2020-07-21 (Tuesday) - Word docs pushing IcedID (B... Jul 21st, 2020 Never 6,408 None -
2020-07-21 (Tuesday) - Emotet infection with Qakbo... Jul 21st, 2020 Never 6,749 None -
2020-07-20 (Monday) Word docs with macros for Iced... Jul 20th, 2020 Never 5,818 None -
2020-07-17 (Friday) - Word docs with macros for Ic... Jul 20th, 2020 Never 4,989 None -
2020-07-17 - Password-protected XLS files Jul 17th, 2020 Never 4,873 None -
2020-07-16 (Thursday) - Word docs with macros for... Jul 16th, 2020 Never 2,520 None -
2020-07-16 - Hancitor infection with an info-steal... Jul 16th, 2020 Never 1,681 None -
2020-07-15 (Wednesday) - Word docs pushing IcedID Jul 16th, 2020 Never 2,823 None -
2020-07-15 - XLS files for Hancitor Jul 15th, 2020 Never 2,008 None -
2020-07-08 - Trickbot gtag chil61 from XLS macros Jul 8th, 2020 Never 2,176 None -
2020-06-30 (Tues) - Valak (soft_sig: mas37) info Jun 30th, 2020 Never 2,965 None -
2020-06-24 (Wednesday): Valak activity - Soft_sig:... Jun 24th, 2020 Never 2,892 None -
2020-06-23 - Valak (soft_sig: mad34) activity Jun 23rd, 2020 Never 2,142 None -
2020-06-22 - Valak (mad33) infection with IcedID (... Jun 23rd, 2020 Never 1,671 None -
Trickbot propagation URLs on Tuesday 2020-06-23 Jun 23rd, 2020 Never 1,796 None -
Trickbot propagation URLs on Friday 2020-06-19 Jun 19th, 2020 Never 2,180 None -
2020-06-09 - Recent resume-themed malspam attachme... Jun 9th, 2020 Never 1,233 None -
2020-06-03 - Valak (Soft_sig: mad29) Jun 4th, 2020 Never 2,682 None -
Trickbot propagation URLs (and EXEs) on Thursday 2... May 28th, 2020 Never 2,854 None -
2020-05-22 - malspam with zip files pushes Valak w... May 22nd, 2020 Never 3,448 None -
2020-05-19 - Qakbot (Qbot) spx122 zip archive URLs May 19th, 2020 Never 2,983 None -
2020-05-18 - Qakbot (Qbot) zip archive URLs May 18th, 2020 Never 3,614 None -
2020-05-12 - Word docs with macros for Valak May 13th, 2020 Never 2,650 None -
2020-05-06 (Wednesday) - Qakbot (Qbot) spx114 info May 6th, 2020 Never 3,564 None -
2020-05-06 - XLS attachments from malspam pushing... May 6th, 2020 Never 2,852 None -
2020-05-05: Links to zip files for Qakbot spx112 &... May 5th, 2020 Never 2,570 None -
2020-05-04 (Monday) - malspam with XLS file pushin... May 4th, 2020 Never 2,659 None -
2020-05-01 - XLS file w/ macros pushes Loader EXE... May 1st, 2020 Never 2,232 None -
2020-04-30 - Link-based malspam pushing Dridex - 2... Apr 30th, 2020 Never 2,616 None -
2020-04-27 - Malspam with password-protected zip a... Apr 28th, 2020 Never 2,279 None -
2020-04-23 - URLs/hashes for Qakbot (Qbot) spx103... Apr 23rd, 2020 Never 3,070 None -
2020-04-22 - URLs/hashes for Qakbot (Qbot) spx102... Apr 22nd, 2020 Never 2,897 None -
2020-04-21 - URLs/hashes for Qakbot (Qbot) spx101... Apr 21st, 2020 Never 2,359 None -
Trickbot EXE files from ".png" URLs on M... Apr 20th, 2020 Never 3,657 None -
2020-04-20 - URLs/hashes for Qakbot (Qbot) spx100... Apr 20th, 2020 Never 2,866 None -
2020-04-17: Trickbot gtag ono38 from password-prot... Apr 17th, 2020 Never 4,695 None -
2020-04-17 - URLs/hashes for Qakbot (Qbot) spx99 f... Apr 17th, 2020 Never 2,659 None -
2020-04-16 - URLs/hashes for Qakbot (Qbot) spx98 f... Apr 16th, 2020 Never 4,236 None -
2020-04-15 - URLs/hashes for Qakbot (Qbot) spx97 f... Apr 15th, 2020 Never 2,358 None -
2020-04-14 - URLs/hashes for Qakbot (Qbot) spx96 z... Apr 14th, 2020 Never 2,586 None -
2020-04-13 - URLs/hashes for Qakbot (Qbot) spx95 z... Apr 13th, 2020 Never 2,784 None -
Trickbot EXE files from ".png" URLs on F... Apr 10th, 2020 Never 1,968 None -
2020-04-10 - Qakbot (Qbot) spx94 - 30 URLs for zip... Apr 10th, 2020 Never 1,810 None -
2020-04-10 - malpsam pushes GuLodader/NanoCore RAT Apr 10th, 2020 Never 4,899 None -
URLs with "/extend/" for Qakbot (Qbot) s... Apr 10th, 2020 Never 2,146 None -
2020-04-08: OneDrive links to zip archives for Qak... Apr 9th, 2020 Never 3,596 None -
URLs from VT on 2020-04-08 for Qakbot/Qbot zip arc... Apr 8th, 2020 Never 3,954 None -
Trickbot EXE files from ".png" URLs on W... Apr 1st, 2020 Never 2,583 None -