malware_traffic

Malware_traffic's Pastebin

81,279 395,568 6 years ago
Name / Title Added Expires Hits Syntax  
Trickbot EXE from .png URLs - Friday 2019-12-06 Dec 6th, 2019 Never 1,119 None -
Trickbot EXE from .png URLs as of Wed 2019-12-04 Dec 5th, 2019 Never 912 None -
Trickbot EXE from .png URLs - Tues 2019-12-03 Dec 3rd, 2019 Never 1,338 None -
2019-12-02 - Hancitor info Dec 2nd, 2019 Never 1,345 None -
Trickbot EXE from .png URLs - Thursday 2019-11-28 Nov 28th, 2019 Never 1,643 None -
Trickbot EXE from .png URLs - Tuesday 2019-11-26 Nov 26th, 2019 Never 1,254 None -
Trickbot EXE from .png URLs - Monday 2019-11-25 Nov 25th, 2019 Never 795 None -
Trickbot EXE from .png URLs - Monday 2019-11-18 Nov 18th, 2019 Never 961 None -
Trickbot EXE from .png URLs - Friday 2019-11-15 Nov 15th, 2019 Never 1,225 None -
Trickbot EXE files seen from .png URLs on 2019-10-29 Oct 29th, 2019 Never 1,661 None -
2019-10-09 - Hancitor acitivity Oct 9th, 2019 Never 1,750 None -
2019-10-03 - Netsupport RAT malspam campaign Oct 4th, 2019 Never 1,496 None -
2019-09-30 - Info from malspam pushing Shade ransomware Sep 30th, 2019 Never 1,258 None -
2019-09-30 - example of malspam pushing Shade ransomware Sep 30th, 2019 Never 328 None -
Trickbot EXE files seen from .png URLs on 2019-09-25 Sep 25th, 2019 Never 946 None -
2019-09-13 - Malspam pushing Shade ransomware Sep 13th, 2019 Never 2,032 None -
2019-09-03 - Malspam with password-protected Word docs Sep 3rd, 2019 Never 6,763 None -
2019-08-28 - File info from today's Ursnif infection Aug 28th, 2019 Never 1,516 None -
2019-08-26 - files from Ursnif infection with Trickbot Aug 26th, 2019 Never 1,604 None -
2019-08-22: Trickbot EXEs associated with IcedID (Bokbot) Aug 22nd, 2019 Never 2,083 None -
2019-08-22 - info on malspam pushing Shade ransomware Aug 22nd, 2019 Never 1,769 None -
2019-08-22 - malspam pushing Shade (Troldesh) ransomware Aug 22nd, 2019 Never 597 None -
2019-08-21 - malspam pushing Shade (Troldesh) ransomware Aug 21st, 2019 Never 1,397 None -
2019-08-21 - malspam pushing Shade (Troldesh) - 2 of 2 Aug 21st, 2019 Never 252 None -
2019-08-21 - malspam pushing Shade (Troldesh) - 1 of 2 Aug 21st, 2019 Never 249 None -
2019-08-19 - Trickbot binaries, "the PNGs" Aug 20th, 2019 Never 1,386 None -
2019-08-12 - Trickbot EXEs from URLs ending with .png Aug 12th, 2019 Never 1,084 None -
IcedID (Bokbot)-related Trickbot binaries seen on 2019-08-12 Aug 12th, 2019 Never 1,176 None -
2019-07-30 - Trickbot binaries, "the PNGs" Jul 30th, 2019 Never 896 None -
File hashes from Hancitor infection on Monday 2019-0722 Jul 22nd, 2019 Never 1,563 None -
2019-06-25 and 06-26 - Malspam pushing Trickbot (gtag: wmd1) Jun 26th, 2019 Never 2,275 None -
2019-06-20 - malspam pushing Nanocore RAT Jun 20th, 2019 Never 1,149 None -
2019-06-13 - Malspam with XLS attachment Jun 13th, 2019 Never 1,174 None -
2019-05-30 - PASSWORD-PROTECTED WORD DOCS FROM MALSPAM May 30th, 2019 Never 1,611 None -
2019-05-28 - EXAMPLE OF EMOTET MALSPAM (2 OF 2) May 29th, 2019 Never 2,009 None -
2019-05-28 - EXAMPLE OF EMOTET MALSPAM (1 OF 2) May 29th, 2019 Never 2,116 None -
2019-05-20 - malspam pushing Lokibot May 20th, 2019 Never 1,461 None -
2019-05-02 - Emotet malspam example May 2nd, 2019 Never 1,849 None -
2019-04-24 - Emote malspam example Apr 24th, 2019 Never 1,944 None -
New password-protected docs in malspam since 2018-04-17 Apr 19th, 2019 Never 1,374 None -
2019-04-19 - malspam pushing Danabot Apr 19th, 2019 Never 852 None -
2019-04-16 - Trickbot malspam - gtag: sat43 Apr 16th, 2019 Never 1,226 None -
2019-04-15 - Lokibot malspam example Apr 15th, 2019 Never 2,170 None -
2019-04-04 - Example of Emotet malspam Apr 4th, 2019 Never 1,707 None -
2019-04-03 - Hancitor malspam example Apr 3rd, 2019 Never 1,237 None -
2019-04-01 - Active URLs for Emotet Apr 1st, 2019 Never 1,089 None -
2019-03-25 - Rig EK landing page from 79.174.13.20 Mar 25th, 2019 Never 1,321 None -
2019-03-18 - malspam pushing Trickbot (gtag: ono1) Mar 18th, 2019 Never 880 None -
2019-03-14 - Info on Trickbot malspam wave Mar 14th, 2019 Never 1,264 None -
2019-03-14 - Trickbot malspam example (gtag day2) Mar 14th, 2019 Never 1,061 None -
2019-03-14 - Malware from password-protected Word doc Mar 14th, 2019 Never 895 None -
2019-03-12 - Qakbot EXE sent to Emotet-infected Windows host Mar 12th, 2019 Never 884 None -
2019-03-11 - Emotet malspam example Mar 11th, 2019 Never 1,607 None -
2019-03-11 - Example of malspam pushing Trickbot gtag: day2 Mar 11th, 2019 Never 827 None -
2019-03-11 - Malspam pushing Trickbot - gtag: day2 Mar 11th, 2019 Never 1,448 None -
2019-03-06 - Trickbot malspam example (gtag ser0306us) Mar 6th, 2019 Never 1,036 None -
2019-03-05 and 06: malware from malspam pushing Ursnif/Gozi Mar 6th, 2019 Never 600 None -
2019-03-05 - Trickbot inject module name tied to gtag now Mar 5th, 2019 Never 809 None -
2019-03-04 - #Emotet #malspam example Mar 4th, 2019 Never 1,207 None -
2019-03-04 - malspam pushes Hawkeye keylogger/info stealer Mar 4th, 2019 Never 560 None -
2019-02-28 - Hancitor malspam example Feb 28th, 2019 Never 1,093 None -
2019-02-26 - Malware from Hancitor infection Feb 26th, 2019 Never 675 None -
2019-02-26 - Example of malspam pushing Hancitor Feb 26th, 2019 Never 1,081 None -
2019-02-25 - Example of malspam pushing Hancitor Feb 25th, 2019 Never 1,016 None -
2019-02-25 - malware from Hancitor infection Feb 25th, 2019 Never 613 None -
2019-02-21 - Example of malspam pushing Hanctor Feb 21st, 2019 Never 1,431 None -
2019-02-14 - Emotet malspam example with download link Feb 14th, 2019 Never 1,478 None -
2019-02-14 - Recent Trickbot weirdness Feb 14th, 2019 Never 2,194 None -
2019-02-14 - Malspam using password-protected Word docs Feb 14th, 2019 Never 3,407 None -
2019-02-14 - Malspam uses Dropbox link to push Formbook Feb 14th, 2019 Never 2,848 None -
2019-02-13 - Hancitor malspam example Feb 13th, 2019 Never 1,144 None -
2019-02-13 - Emotet malspam example with PDF attachment Feb 13th, 2019 Never 1,247 None -
2019-02-12 - Emotet malspam example with PDF attachment Feb 12th, 2019 Never 1,810 None -
2019-02-12 - malware from Hancitor infection Feb 12th, 2019 Never 1,119 None -
2019-02-12 - Hancitor malspam (USPS theme) Feb 12th, 2019 Never 1,434 None -
2019-02-09 - Fake Updates campaign pushes Chthonic Feb 8th, 2019 Never 1,222 None -
Since 2019-02-04 - Trickbot EXEs as PNG: Sin, Tin, and Win Feb 8th, 2019 Never 1,292 None -
2019-02-08 (Friday) - Trickbot malspam (gtag: sat36) Feb 8th, 2019 Never 1,072 None -
2019-02-05 - Trickbot malspam - gtag: ser0205us Feb 5th, 2019 Never 1,630 None -
2019-02-04 - Trickbot EXEs as .png from 185.68.93[.]30 Feb 4th, 2019 Never 995 None -
2019-01-29 - Fallout EK possible exploit Jan 29th, 2019 Never 291 None -
2019-01-29 - Fallout EK landing page Jan 29th, 2019 Never 280 None -
2019-01-29 - Fallout EK (HTTPS) sends SmokeLoader -> AZORult Jan 29th, 2019 Never 1,202 None -
2019-01-29 - Malspam pushing AZORult Jan 29th, 2019 Never 1,646 None -
2019-01-29 - example of Emotet malspam Jan 29th, 2019 Never 1,322 None -
2019-01-28 - Trickbot malspam (gtag: ser0128us) Jan 28th, 2019 Never 1,033 None -
2019-01-08 - Trickbot EXEs as .png from 107.173.104[.]203 Jan 28th, 2019 Never 746 None -
2019-01-28 - Hancitor malspam example Jan 28th, 2019 Never 1,426 None -
2019-01-28 - malware from Hancitor infection Jan 28th, 2019 Never 1,226 None -
2019-01-23 - malware from Hancitor infection Jan 23rd, 2019 Never 4,271 None -
2019-01-22 - Malware from Hancitor infection Jan 22nd, 2019 Never 826 None -
2019-01-21 - Sextortion email example Jan 21st, 2019 Never 2,403 None -
2019-01-18 - Password-protected Word docs pushing IcedID Jan 18th, 2019 Never 3,233 None -
2019-01-16 - malware from Hancitor infection Jan 16th, 2019 Never 632 None -
2019-01-14 - Trickbot malspam (gtag: sat33) Jan 14th, 2019 Never 892 None -
2019-01-08 - Trickbot EXEs sent as .png from 198.23.252[.]10 Jan 8th, 2019 Never 758 None -
2019-01-04 - example of Sextortion spam Jan 4th, 2019 Never 1,762 None -
2019-01-02 - Phishing email with link to fake login page Jan 2nd, 2019 Never 891 None -
2018-12-31 malspam example: Excel attachment pushing AZORult Dec 31st, 2018 Never 256 None -
2018-12-31 - malspam uses Excel attachment to push AZORult Dec 31st, 2018 Never 807 None -