Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save silence-is-best/da581fc279e34d1cc11d93e29333f45b to your computer and use it in GitHub Desktop.
Save silence-is-best/da581fc279e34d1cc11d93e29333f45b to your computer and use it in GitHub Desktop.
January Malspam Campaigns
Date,Details,Email Payload Type,Users Targeted
1/9/2024,Payment Failed: Update Your Payment Details to Avoid Subscription Interruption; pdf -> hagga -> orogin logger,Attachment,2
1/10/2024,Inquiry 37567 Appendices A, B, D, and E; 7z -> loader,Attachment,2
1/13/2024,Subjects contain Agency Appointment; zip -> snakekeylogger,Attachment,7
1/13/2024,FLF7992/22 // Shipment; zip -> snakekeylogger,Attachment,3
1/15/2024,Your UPS Parcel was delivered; gz -> originlogger,Attachment,2
1/15/2024,PO 4500082036; zip -> remcos,Attachment,3
1/15/2024,PDA and PORT INFO for 69 x 20' IMO CONTAINERS; zip -> snakekeylogger,Attachment,3
1/16/2024,Subjects start with Invoice from DSV: pdf -> zip -> js -> wikiloader,Attachment,369
1/17/2024,New Quotation 5665900481XXX024; rar -> oroginlogger,Attachment,3
1/19/2024,Re: Quotation Samples; img -> originlogger,Attachment,22
1/22/2024,RE: Incorrect Bank details/PAYMENT OF EUR 92320/PO881620-2024/JAN; tar.gz -> modiloader -> remcos,Attachment,4
1/22/2024,Re: Payment USD 85000; zip -> originlogger,Attachment,2
1/23/2024,Re: Re: Fwd: DIGITAL ESSENCE INVOICE; tar.gz -> modiloader -> remcos,Attachment,4
1/23/2024,New Inquiry: RFQ.NO_8877; xlsx -> originlogger,Attachment,2
1/23/2024,Inquiry 37567 Appendices A, B, D, and E; 7z -> originlogger,Attachment,6
1/23/2024,Payment Advice - Advice Ref:[A25aZLcK5lCT-IN]; tar.xz -> oroginlogger,Attachment,2
1/24/2024,Purchase Order.5643; z -> originlogger,Attachment,2
1/24/2024,Networkonecss INV-103902 overdue; pdf -> vbs -> remcos,Attachment,4
11/29/2024,New PO# 10402475; z -> originlogger,Attachment,2
1/30/2024,Confirmaci�n de cotizaci�n; z -> originlogger,Attachment,4
1/30/2024,Quotation request / PROFORMA; img -> originlogger,Attachment,2
1/30/2024,RFQ NEW ORDER; doc -> originlogger,Attachment,2
1/31/2024,Header from noreply@cevalogistics.com; pdf -> zip -> js -> wikiloader,Attachment,216
1/31/2024,Remittance Advice No. 43631; lzh -> guloader -> originlogger,Attachment,23
azorult, 648a3005b5a4ff2aecc834667780d073efd5d540d4b8f65963ce761f4278b334, http://blbl1.shop/BL341/index.php
formbook, 57bf60dae149215611af79b1ebeb1cfdd1d3a73d32e48035894971eb4a69566d, kizuna2.vip/jk56
guloader-originlogger, 41291c4fe5bf7c5f0277dc55da878d313dbb06edf44201c04576495a2cabf881, mail.marsoir.com
guloader-originlogger, 47a05b7efdfad238172f1e804fb8a681b88281fae68e9a6efabe9b175c1572f7, mail.profilatieffe.it
guloader-remcos, 6e6ecd38cc3c58c40daa4020b856550b1cbaf1dbc0fad517f7ca26d6e11a3d75, 85.209.176.69:57484
hagga-origin, 2036c55eeff25d6200dcbf7d4b91bf4137c9829e6435a451ded924c828ec662e, https://api.telegram.org/bot6934635674
lokibot, 7eb68960a6b79e0705d3ca8d54744d29a8744442ea6f232d961558cb1e31a561, http://roof.spencerstuartllc.top/alpha/five/fre.php
lokibot, 9a32cdc7e68af6220b82c21e76d1eda4a4a822df3fc75dc642538c1ef4f50901, http://kbfvzoboss.bid/alien/fre.php
lokibot, d49936b037eb6ad03ca37d81a0dfc69946e36c380d6f3129319eb8afa1dcdb53, http://kbfvzoboss.bid/alien/fre.php
modiloader-remcos, 08d763ba6c1ef0fb1e1774e9050e6eae1e61cd4149dcb5334f6e73e9afb6cff3, 192.3.101.8:55677
modiloader-remcos, 207a9086d1da3aa133fb4cb8628ad87f16d27059ad86314825b57d86669e9a03, 192.3.101.8:55677
neshta-originlogger, 7e4178777e66874affc0c4e95846d4fadd7b9d39252ef984ede3e13ffdf0140a, mail.profilatieffe.it
originlogger, 0922bbbf638842a281530ad572da59ef6ae2326e49671b1f97b43c9031d95ad5, https://api.telegram.org/bot6831365897
originlogger, 0bb832320a92ba68c398f71058c99556988795e84f3838ffa8143921c3ed04c7, host2069.hostmonster.com
originlogger, 15ed690489e8c1fe0d2e74ed0a241eb1b66a440a542744dbb540e4a0c171b89a, mail.topcats.com
originlogger, 1994ca93abdb13e25fecc514dd06ae7853525f8495e006dedbad9972dd27955e, mail.babychitto.com
originlogger, 1a83ba2bad08f7638bd60d2c15153c028f42048e82adb3702c33c791a4c85c79, mail.bernardo-hrvatska.com
originlogger, 1d132becb6f5aa7c2597944d9fa196bacf8cea871ccbdd09ce64cab06f581583, cp5ua.hyperhost.ua
originlogger, 2b6b6d4b6814af85d658ca6735b150cbbdc3b0a7a37939a5c6c12b6e36ee4218, mail.bengalleather.com
originlogger, 304f5f10e6586f04beecd03dd27c217893c449cc7a3addb3816e4befb2bff590, https://kalnet.top/_errorpages/obizx.exe
originlogger, 44d966ac7046e1860d9f18368b2c190299a7de106f212814543b3d373552ff73, mail.gasplants.quest
originlogger, 59bfb982d029cacbcb298fb5f5cd32d30a4420c92cca120304e144aad3608068, mail.topcats.com
originlogger, 5a88ba99a9a102c08cbc44679f5bf078a79134bb99d0ca92fae9a8930500211b, mail.showpiece.trillennium.biz
originlogger, 6a861eb0176a0f7e0c4d69f2a65856d739bd4829448e72add40fabb9bf439634, mail.profilatieffe.it
originlogger, 700fd6c408ce5d0e3953026e355db953dd3ca0850fedba2f0c772f7dcb18d80b, mail.precise.co.in
originlogger, 81e7f10e3da2b0ae2e6785fa2126c3e76c3d11007ded45f88fd08390a25e7e69, smtp.rtcanaamairobi.com
originlogger, 8b44d22c62f8f7f749ed63a3ae1ea5068bdac5db4fbccec5635f47a6fd27dbde, mail.southerngroup.co
originlogger, a3268fd103ce714411b447c75854565ddf366535c6f47641893f0d78f0482bb8, mail.precise.co.in
originlogger, a47ba5991ade84ef2d1e978995208bfe43bf3be9d7fc37fe24ff9ab87e9e6f22, mail.awelleh3.top
originlogger, a6a4e8b6276ff31b64a3c12858ca9c231972a8c0f12a89c01b4f32d2b95ed200, https://api.telegram.org/bot6632122066
originlogger, b47914d632508339a012e07cc4030b35b25a78665513276c26496affefd01b90, mail.giroplastic.com.br
originlogger, bf8d6a6c87df124721dc95f7420c67d15668a14865d5719505737e8d78bb335c, mail.profilatieffe.it
originlogger, c3cbff3aed1ec835babf2cb779d38d66ed9328662fb049819ce7d199e693409b, mail.amtechprinting.com
originlogger, c63a10d8a92a5348801360fb963792f3f4309d6801eee6fa63038333f6b5d830, smtp.crane-eletronics.com
originlogger, c6aabca4f47471641b63db1009d086e651703eed4d1c0da3bc2b810669760714, mail.tecnosilos.com.py
originlogger, c7e758fd23e2e8806a99e41d5c69d17450e330e69d4ab0a911aee9a878128eff, mail.tecnosilos.com.py
originlogger, c99591e2e00cc7625f8b8af1eeb04b19b76e5b44f74669fe6b899fbc7b201f6b, mail.kp.gov.pk
originlogger, cdc07215534b2a013cc2ab666d9a37eaebf478aa389489416159fd7034c2670d, cp5ua.hyperhost.ua
originlogger, d31b8d373badf8390c91b27d173cbfc88adf7701e08d222d05f2d28518ded326, mail.cyber.net.pk
originlogger, d3cd8c4c724b78139d2edc50e43022c924255409c720d8437b74e4738534093d, mail.amtechprinting.com
originlogger, d4de5078a15d847876ba1af8c9d49b5449eaf21515b7a70307d42ced8c335ebd, mail.imperiodoradosa.com
originlogger, d5068bc4969d0062866e4d3c3e62aaab1ae73a17e0f0a8c7e14510d9af5488c0, mail.newbrands.biz
originlogger, d5b58663ecebfcc7b6093c8d0fbea2539cbcaeaa00d3f46f38b60353223ace6f, mail.showpiece.trillennium.biz
originlogger, e42a258d803f7ad074adc3ece7280404f04eb0f62fb97222dec9cfe87238bf5c, https://api.telegram.org/bot6946449919
originlogger, ea89d821d04aee27aa911b6004ef645d3119e8cf21a60fe180cd27a9b1472034, smtp.crane-eletronics.com
originlogger, ee69b74d0f0dd59fcd87304863626efb727ad6255bc29a7d48b7a441390dff1a, ftp://ftp.elquijotebanquetes.com
remcos, 119e1eb6d38ad141db3a7dcb1b2b3d9e6fd39dbcae99ffbe9f9030acf324bb60, 103.169.35.140
remcos, 21675c3e3a959bb2060603038f45fc5aad17a66c5d6556cb8777852d624aa763, ominiblog.store
remcos, 59c2e028175d2008b4ac3997eb8429d74a7b02981098f94c4dcb5d12ecfe009e, 45.95.169.102:2404
remcos, d5bc991d8b0e51e45a1b9b9baa71dda7f7dfd8e769e3a641d0cda1077bd01b04, 198.27.121.194:2024
snakekeylogger, 1860fb1b0d09c48a73d706886b6454756c7532f2b9cdd61564a3f79a796784e8, aborters.duckdns.org
snakekeylogger, 2179d1b6ba7587b545ee9f9c7c1cd05e06b0573eb0f063f8196c7650cf93c4b7, valleycountysar.org
snakekeylogger, 4157b7a4a5f6911cd322d66624ff39025aac8705316eac85da8a3df0df6ca77e, http://aborters.duckdns.org:8081
snakekeylogger, 44e30707c5d0501432e43da59167f8751ebeab3de80d6138a81f46b01a7e6a2e, http://aborters.duckdns.org:8081
snakekeylogger, 4a8e27dc5721e437f5728054733258a2d92cbe90454a8f2e7c8a98b6aed0daee, http://aborters.duckdns.org:8081
snakekeylogger, 56a80a377a4c55c505ffa790f6b18f0336892caff53ea252838c3183440e52d5, http://aborters.duckdns.org:8081
snakekeylogger, 6c7b0d0545f5d55e896d26d244a411024cabbdb26c96744839e22c16a4495659, varders.kozow.com
snakekeylogger, 931ded16af5bdb188c63d5c77a5c332b809fda77cf7c6528202259342a23bf39, varders.kozow.com
snakekeylogger, dfc2549bb01c896ce859ef5b081d26128ea36cf31321450ec9c3b89f6fbcd620, valleycountysar.org
wikiloader, 2353eb7aa2bc61c3ca2340d6a619774e8a446de188bcf616411e98ba4bab54ca, https://thekostenfamilys.com/m1b7o3.php?id=1
wikiloader, 2add886330db1480da7314ee38428ca79af04f8c461c3bbbd68e202bb5f4c415, www.hiperplatinum.com
county@valleycountysar.org
trainee@valleycountysar.org
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment