home.social

#malspam — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #malspam, aggregated by home.social.

fetched live
  1. Over the past days, active #malspam campaigns targeting LatAm users 🇦🇷🇧🇷🇲🇽 have been delivering the Grandoreiro banking trojan 🏦💰

    📧 Email ➔ 📜 JS file ➔ 📑 Fake PDF download

    Final payload is hosted on MediaFire 🔥 free file hosting

    C2 network traffic is rather trivial to detect as #Grandoreiro is using Embarcadero Delphi compilation tools' HTTP user agent 🖥️⤵️

    User-Agent: Embarcadero URI Client/1.0

    🔎 Botnet C2 domain resolved via Google DNS-over-HTTPS (DoH): devilmaycry.servehumour .com 👀

    📡 Grandoreiro botnet C2s hosted at AWS:
    54.80.154.193
    54.91.129.132
    54.91.223.28

    🌐 Payloads URLs:
    urlhaus.abuse.ch/browse/tag/Gr

    📄 Malware samples:
    bazaar.abuse.ch/browse/signatu

    🦊 Relevant IOCs are available on ThreatFox:
    threatfox.abuse.ch/browse/malw

  2. PSA: If you're seeing links that literally start with _wildcard_ in #malspam, these are dropping #screenconnect (usual relay c2) via #zoom update lure.

    1f7ab5418d489fdd2fb392ada3accc77c13586f94f059ee8e5cc83c0974b614b

  3. A csv formatted list of #malspam campaigns that crossed my path in July to include #malware type, subjects, c2's, hashes, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  4. A csv formatted list of #malspam campaigns that crossed my path in June to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  5. A csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subjects, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  6. An on time (yay) csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  7. Trust this “Amazon” phishing email in Japan—and you’re Prime sashimi 🎣 🍣

    Looking into our malspam data, we identified an active campaign impersonating Amazon and targeting Japanese citizens. The emails use subjects such as 「至急 Amazonプライム会員情報の確認」 (“Urgent: Confirm Amazon Prime member information”).

    The URLs within the emails ultimately lead to an Amazon phishing page, but only after routing victims through a TDS. Interestingly, instead of keeping the TDS step invisible, the actors chose to show it off—repackaging it as a reassuring security check.

    Upon clicking the link within the email, victims are first redirected to an RDGA TDS domain, where fingerprinting occurs. If the user does not match the targeting criteria (e.g., connecting from outside Japan), access is blocked. If they do match, potential victims are redirected to a second RDGA domain.
    This second and last domain is not a TDS domain, but funny enough, these actors decided they would emulate it anyway!

    At that step victims are already at the landing page but instead of immediately displaying a standard Amazon phishing page, the website displays a CAPTCHA and fake console interface simulating environment fingerprinting checks to “make sure your environment and connection is safe” before "proceeding to the landing page". Ironically, part of their message is true: fingerprinting did happen one domain earlier. It just wasn’t for the user’s benefit—it was to make sure the environment was safe… for the scammers. A few seconds later, without added user interaction needed, a fake Amazon login page is displayed.

    Domains samples:
    qqc10c[.]cyou
    51wang11c[.]cyou

    #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #scam #phishing #amazon #malspam #email #fingerprinting #japan

  8. A very late (due to work travel) csv formatted list of #malspam campaigns that crossed my path in March to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  9. A csv formatted list of #malspam campaigns that crossed my path in February to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  10. A csv formatted list of #malspam campaigns that crossed my path in January to include #malware, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  11. If you've been experiencing these new #malspam with @Action1corp #action1 RMM, there's a tasty lil file called C:\Windows\Action1\what_is_this.txt that's everything you need to know:
    app.any.run/tasks/a38ca435-f03

  12. A short (and late due to vacation) csv formatted list of #malspam campaigns that crossed my path in December to include #malware type, subject, hash, c2, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  13. Happy Cyber(crime) Monday. Someone is sending out these bogus "e-signature" notifications as #malspam.

    They lead to a page on Google Drive that has an interstitial link. When you click it, the page pushes an installer for N-Able Advanced Monitoring Agent, a commercial IT remote management tool. virustotal.com/gui/file/5ddcff

    This is just the latest evolution of the attack I documented on the @Netcraft blog before the holiday break: netcraft.com/blog/shared-docum #spam #malware #RAT

  14. A csv formatted list of #malspam campaigns that crossed my path in November to include #malware type, c2, hash, subject, and some email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  15. A csv formatted list of #malspam campaigns that crossed my path in October to include subject, hash, #malware type, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  16. Some #evil gotoresolve unattended (@LogMeIn cruft) at:

    https://padoneeronaccounto365\.top/adobereader.msi

    Company ID: 1441449199376154640

    via docx #malspam

    a665e6c5d05e02f5812c2bd1e4d405d7b7395dbe94fd380e6b1f1ad35bfd8b02 on the msi

  17. An embarrassingly small csv formatted list of #malspam campaigns that crossed my path in September to include hash, subject, c2, #malware type and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  18. A sparse and late (due to holiday and <groan> jury duty) csv formatted list of #malspam campaigns that crossed my path in August to include subjects, hashes, c2, #malware type, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  19. A semi-late (due to Friday off) csv formatted list of #malspam campaigns that crossed my path in July to include #malware, hash, c2, subjects, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  20. A semi-late (due to illness, nothing major) csv formatted list of #malspam campaigns that crossed my path in June to include subjects, #malware type, hashes, c2's, and email exfil addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  21. A (sparse) csv formatted list of #malspam campaigns that crossed my path in May to include #malware, subject, hashes, c2, and email exfil addresses.

    gist.github.com/silence-is-bes

    #retrohunt

  22. A csv formatted list of #malspam campaigns that crossed my path in April to include #malware type, c2, hash, subject, and email exfill addresses:

    gist.github.com/silence-is-bes

    #retrohunt

  23. 2025-04-17 (Thursday): I found an example of #MassLogger malware sent through #malspam. The infection traffic indicates stolen data sent to a mail server at mail.bouttases[.]fr.

    Details at github.com/malware-traffic/ind

  24. Last week I posted a thread about a #spam campaign delivering a #ConnectWise client as its payload. As of this morning, the threat actors have changed the payload (virustotal.com/gui/file/30e1d0) and it appears to try to connect to the address "relay.noscreener[.]info" which resolves to 104.194.145.66.

    Embedded in the installer .msi file is a file called system.config, which contains this domain name and a base64-encoded string.

    The fake Social Security website is still being hosted on a compromised site that belongs to a temp agency based on the east coast of the US.

    Previous thread:

    infosec.exchange/@threatresear

    #malware #phishing #malspam

  25. However, because this attack has been going on for two weeks, some endpoint protection tools (well, about a third of them) are catching on that this particular file is bad, and should feel bad.

    virustotal.com/gui/file/13d71b

    The most important lesson here is that attackers always come up with new ways to evade detection. Using a commercially available, normally legitimate remote access tool with a valid cryptographic signature lets the attacker bypass some kinds of endpoint detection.

    Remember to check the From: address in emails, and the destination of any links they point to. You can do this by hovering your mouse over the link without clicking, and waiting a second. If it says it's from the SSA, but it isn't pointing to SSA.gov, then it's a lie.

    If you find content like this useful, please follow me here, or on LinkedIn: linkedin.com/in/andrew-brandt-

    9/fin

    #spam #malware #malspam #ConnectWise #attacks