Skip to content

Instantly share code, notes, and snippets.

Show Gist options
  • Select an option

  • Save silence-is-best/49cbc51145478ed68d06e02e14ddc135 to your computer and use it in GitHub Desktop.

Select an option

Save silence-is-best/49cbc51145478ed68d06e02e14ddc135 to your computer and use it in GitHub Desktop.
February Malspam Campaigns
Date,Details,Payload Type,Users Targeted
2/1/2026,Your Social Security e-Statement Is Ready � View Using the SSA Gov Viewer App; zip -> screenconnect,Attachment,2
2/1/2026,Final shipping documents; zip -> phantomstealer,Attachment,2
2/2/2026,STATEMENT OF ACCOUNTS DEC.2025 USF; zip -> bat -> guloader -> phantomstealer,Attachment,3
2/2/2026,FW: SS24 NEW TPI E407SH005 / E423SH006 RIA; docx -> rtf -> xloader continued to 2/4,Attachment,3
2/2/2026,Fw: RFQ-S75502262N; z -> xloader continued to 2/4,Attachment,2
2/3/2026,Signature Via Docusign Required; link -> msi -> screenconnect,Link,17
2/3/2026,You have an important notice from BMO Bank; link -> msi -> screenconnect,Link,15
2/4/2026,Re:Order H600287395; rar -> guloader -> phantomstealer continued to 2/6,Attachment,7
2/4/2026,PURCHASE ORDER AND SAMPLES 2026; docx -> rtf -> vbs -> xworm,Attachment,3
2/8/2026,???? PO017642; js -> xloader continued to 2/16,Attachment,98
2/8/2026,Your Social Security e-Statement Is Ready � View Now; zip -> cmd -> msi -> screenconnect,Attachment,3
2/10/2026,Re:Payment Confirmation|Re:Revised Purchase Order; rar -> phantomstealer continued to ,Attachment,10
2/11/2026,Payment Advice - Advice Ref:[A1XpEM04cqrK] / Priority payment / Customer Ref; zip -> xloader,Attachment,6
2/12/2026,Re: AW: Purchase Order sheet please confirm (AL Shabiz Trading LLC );zip|tar -> darkvision continued to ,Attachment,12
2/12/2026,RE: PURCHASE ORDER_12257; rar|r15 -> xloader continued to,Attachment,8
2/12/2026,Your Tax Form 1099 / 1042-S Is Ready.; link -> msi -> screenconnect,Link,3
2/13/2026,Wire Transfer Invoice|Wire Invoice Transfer; link -> msi -> screenconnect continued to 2/17,Link,12
2/14/2026,Re: Product Order; zst -> xworm,Attachment,3
2/16/2026,Re: Proforma; r15 -> xloader,Attachment,2
2/17/2026,Re: CHANGYA NEW ORDER|RE: PP Samples Material; rar -> xloader,Attachment,4
2/17/2026,New Order - VRF/BT/2025/ENG/037; z -> xloader,Attachment,4
2/17/2026,Sender domain is california-rent-a-million.staging.designinternal.com; link -> msi -> screenconnect,Link,34
2/18/2026,??: payment regarding shipment; z -> xloader,Attachment,4
2/18/2026,PURCHASE ORDER 000389847;zip -> vipkeylogger,Attachment,2
2/18/2026,EFT Payment Remittance; img -> js -> phantomstealer,Attachment,8
2/20/2026,IMPORTANT ACCOUNT DOCUMENT AVAILABLE; pdf -> link -> screenconnect,Attachment,4
2/20/2026,COMP PAGO; rar -> vbs -> reverseloader -> vipkeylogger,Attachment,5
2/22/2026,Payment Success; link -> zip -> url -> bat -> zip -> asyncrat continued to,Link,58
2/24/2026,THANK YOU; zip -> js -> ps1 -> purelogs stealer,Attachment,5
2/24/2026,Factura pagada; zip -> darkvision,Attachment,2
2/27/2026,FW: TICKET REJECT ERROR; xlam -> hta -> xworm,Attachment,3
asyncrat, 8d2327dddd220eca141da7d0c35c7f987be541e7cd42ea15b7d81458f27f3e5b, volvogroup20.duckdns.org
asyncrat, 93282e12dd190c462c9f7c1394dd18194773c3fbefe76f8972a7369e1d976ac9, yernbdsakpo.duckdns.org
centrastage, de1d6ba7791d6148f8c8cfa60a639953e7086517b8525bdaafd8b790d5b2e249, 03cc.centrastage.net
darkcloud, 9992e4177343a1227f6a60f77f6556f5df92b30ce35b5521ee4156bb4fabb844, ftp.khenghong.com
darkvision, 9f29563ca323046c2ff4f7ee64c298221dd03a4cd54fc1b56c875b293cfe03d6, toolz.3utilities.com:3321
darkvision, b1c7d89f04a4a9a2729f6030b581e5a7cfb2afe766b36c80cfad5ece7ecccfed, toolz.3utilities.com:3321
darkvision, fb76ed9669c3c728806fa4d349e46bcec2e51f474ac829269e3713f3909c051b, toolz.3utilities.com:3321
donutloader-snakekeylogger, a928bab469a458f3d664ab849821bd544297ebe2a4a7360705e5d44bf7a3457e, https://api.telegram.org/bot7792051628
donutloader-snakekeylogger, f767081fc9067dbb957b86751a700b4e77c94155917c48ff13f50ce837c2a3fc, https://api.telegram.org/bot8190731752
donutloader-xworm, 11894cc842ed9eed7367aa086dbf35bb9bb913709117f767b39c7da5d798f145, 204.10.160.190:7003
donut-vipkeylogger, 0590bcf46064f75a3383dbb84c3f1365b5684f414e0dd0de4504034aaeedf088, mail.taikei-rmc-co.biz
expiro, 027b246202821c3564dcb1c7bdab3c76bbf77c5b98bb8d862616eb3352ed3fd1, vcddkls.biz/mworvfafggtw
guloader-phantomstealer, 04c53eb6c67558ecfb59da6f38498776405570a4f1a99f61934a53173a40a36a, mail.lodenrandmarines.com
guloader-phantomstealer, 12db648c3d516bb4210f37388077273757ea792168a6c32a9c0210cbfc7c01f9, mail.lodenrandmarines.com
guloader-phantomstealer, 40132c04a7534bc0a1cfc605426fe5e409f64565712e3c972c1381d8639748b4, mail.dibqatar.com
guloader-phantomstealer, 43b15dbf32e4154e6c1ab84a79de344a2c850ff60f06b760b92773e860977f6c, mail.lodenrandmarines.com
guloader-phantomstealer, 6449bd456e9c56bb907670260049c1eae3b3a8e01913839f168bbdfcc1883e43, https://api.telegram.org/bot7970721019
guloader-phantomstealer, 80f0d90ed824fb3229008d61135bbe798b97b93e8b8686173c23db05a4a877a1, mail.lodenrandmarines.com
netsupport, 7ce751500e39727ad51617bdcb3b0a9f56bf3b8fe8bdf05b8940d9484c08da1c, MonkeysForest.com
originlogger, 1f9188b926fd1bf32c8731d981cbd0be675b10cc1376f0544f01b99486f56e3a, petro4prime.ydns.eu:5909
originlogger, 2cbe0104d0a55f21c2f0e895a50df2ffdbdebfe2e020c7b5dead6aaeb233467e, ftp://ftp.duct-master.com
originlogger, 6f998e066e89d74f97f68b8b300cbf96f10df8bca0f96b78082e54ae578c6808, ftp://ftp.aventour.com.mx
originlogger, a2909324ee9763d9c6b48ed73d2bb082d622eebd35d22641da2894d9cf94cea9, ftp://ftp.aventour.com.mx
originlogger, a72181561540f1c1d48dd8f33fe4b502fe8b1fdf27a908b035296276638af564, ftp://ftp.aventour.com.mx
originlogger, a9b670ff357cbb942a795c8524999072cd9466486b9c28b5b0d809b01547293b, mail.eastsidedynamic.com
originlogger, c20aff27123c081640839c0e1e3663f4e2cb25c3d5a697aae68f416e6e7e350c, mail.taikei-rmc-co.biz
phantomstealer, 14f5baba86e43ea12f13c38bac263bd7a0a58de989378f52033f2fc282b0f64f, mail.lodenrandmarines.com
phantomstealer, 16a077a72759886ef0d75bf397268220526228d79177fa37242a04d176106dcd, https://api.telegram.org/bot7784142559
phantomstealer, 16f331e6c7c5ec95bdd763d83516bb540e84aa165416a63861c9b3dd523a1905, gimas.bg
phantomstealer, 192369a2ed9ca8c9c3c4c9685d619678ef0d6f0dc7e2629ebc9a840e92cd699b, mail.taikei-rmc-co.biz
phantomstealer, 1f74eb450f583a09fc804416534b66ca1be10563cd0be2cd0e2a0b8437199ac1, mail.ekeindia.com
phantomstealer, 2babb5268496a4b5231d8d58e3f84ebe220ab2ddea277ec9910bdbdffb572f4d, mail.lodenrandmarines.com
phantomstealer, 408fbffb330ad289ae8e39bd708a3ccdb55ac31358d4a82ccea4f1c705308c2e, https://api.telegram.org/bot6184405374
phantomstealer, 49c7caba0e93c51ed5fb1f246fc884b944d95a5ee19a3c7e9bbb43f7eed5255d, https://api.telegram.org/bot7970721019
phantomstealer, 76b44a01a26e771a473e255999e0026a153c9dc30271f4f9908f61cd4dd4ca19, ftp.corwineagles.com
phantomstealer, a578989343df52383e1009d0f1fb9773a96fbb83d1548c557b2f619ef224d368, https://api.telegram.org/bot7246162905
phantomstealer, ab69b8d4f4daadb6f01643fb6c6c4fabf365a208524827df4bd1fdab20c14f39, mail.lodenrandmarines.com
phantomstealer, b175597c75ec189231776234a5aa5f14c6f5d65d18ce038a3555a8de3fe818f1, ftp.henfruit.ro
phantomstealer, b20359d275dd556b8a25531dd2acc933c945e989855fdc881c438cfb0cb471a0, https://api.telegram.org/bot7246162905
phantomstealer, b5688e630ded6c873e5680ebac79d2fde8882ff27795a4b2b809745c58cfd173, ftp.henfruit.ro
phantomstealer, ce9f7f995a6dc24581ba0af01696c4dbcec1a941c2111ff6f7cbc8fb51368961, ftp.henfruit.ro
phantomstealer, fee466f5b375bb863ec7e353f4c94af78159753c0a12ed2df01779b2933af183, https://api.telegram.org/bot8291947048
phantonstealer, 75e1e4ec37074fe7a1aeb31ce3932192963f8423c6b9a02e41eb25f9f14f8ec6, baxeeon.shop
purelogs, 9f60f244e5c10d02100884aa438b2d44ef7d81b4dc34e41df092af464f831bad, 38.49.210.126:8443
remcos, 0ed61e662938f8314c4604036665c8ebc165d296def4bd8fe2f11dd9b0edf6e7, mikantiz.ansmtpariba.com:2091
remcos, 1a617773705434949b2c19d3dc860a2aa57ddf1de6b5e09ed54276f59d787b67, 172.245.195.233:2404
remcos, 21c4eeb21c8467489098c06e56b468460f8146ad7ca188d71887f1ec15650d34, hansonscarriers.com
remcos, 77940063fcd0f276c574ea55967eb0834939e8d201922be88ffc53309351a3d1, 161.248.178.69:2404
remcos, fe2dcfff84a13a6ef8835a51a70d8d7b77e98635fbb2524f4fc03b5cb5f9a62a, mrekuro.hopto.org
screenconnect, 018b282ff110940371cd260432d37b8689b50052580dbd994166a5f3dddaa114, instance-lfvo6e-relay.screenconnect.com
screenconnect, 039359cb8c082a4fe2c867b1bb6ed159615ed4cfaf4e6532ddbdd16bf53ebfe8, 178.173.247.79
screenconnect, 18344051cf87e5ccb46184525a62124cb11d50a23f569c6eb939e56f6a7dc42c, instance-lfvo6e-relay.screenconnect.com
screenconnect, 42f7a72fff3dac1abe4ae7de2e8fde541f2922ad49e57cd11f9c2220cba878f5, instance-cl09jp-relay.screenconnect.com
screenconnect, 45cb9f31d81e497fa60cc9f07312f11534f1067b44acfd2e0ebae7616b807161, instance-oll0zp-relay.screenconnect.com
screenconnect, 4f5bcf1dc0abe80ab25a2b68e65505c42aa4757858d97c73bc619195da2bcc08, instance-h98onv-relay.screenconnect.com
screenconnect, 512afccb10313d5cf15cb3ccefda19a3634388457784a198119be80de158f657, 38.240.48.213
screenconnect, 8066ed29d40a853f2884e0be50157cc03a36d2a9c5b783c92ead87d396ae406e, relay.dvfuckerg12.net
screenconnect, 85b7d19ad16bac51df0957a162ddbf6ee29678da61286a4ced3ddad276916e66, relay.t0up.top
screenconnect, aca624e592d78d4a2b09d2fdc46578c8ca8ce105048ac6bee0b339e77d61ebeb, instance-f6ha0z-relay.screenconnect.com
screenconnect, afbdf3912f1543037cc37cf51840732792dad2f2afcc312809989ce11dfa9e25, instance-xqtbin-relay.screenconnect.com
screenconnect, bba9906fff9b1a2378f4a3ed196efb64ab5f6ad61c9805be5e3a17408552cac4, relay.screenconnect.com
screenconnect, c061c4672941543c251871f87c5e5b9ca093af3ab5c12f8a1469ca7d364b3e9e, instance-kvo5kb-relay.screenconnect.com
screenconnect, c43b022395b7faa0745f3a6ba0384cdb309d4f4ca62f27a9d17328d8e99cc364, 38.240.58.33:8041
screenconnect, e3b2dd519e4ce14de69db795fbb8895388abe7eb40e3f0c93214e07c9ef35afa, 31.57.147.191
screenconnect, ee13138b213f3ec6419561de05afe0466c264bb1a20c7afee627180e55eebc77, instance-jtu28g-relay.screenconnect.com
snakekeylogger, 1cdf0124ae3cc7bfd3182b1083a44a76d93104b444e642df4c3c0a8975305deb, smtp.gmfautomation.com
snakekeylogger, 254b3331e952c249fa7564e85bd1f968d53c7fdd4838fcf70d9b8abe9acb32c4, mail.fbindustries.com
snakekeylogger, 40fc8d0fe590f2281efe1af792f90654aff809c3a445c2fc94f6f671c6faaa5d, mail.transman.gr
snakekeylogger, 4b7a405d2d1a9411a60f5316c9a77c64955683686aec9d2aa74527d177f6ada6, https://api.telegram.org/bot7685437193
snakekeylogger, 5d8629c84b9308abeaf0ae4b3bd27b16d792c40d3c28ce3dae71aa262c1532f9, hosting2.ro.hostsailor.com
snakekeylogger, 9ea0b342f8074e48a115a001ec4d04da500ae2c39824dd6c33f0d3375843b185, mail.seaposvc.com
vipkeylogger, 3c7ae1ee34ef942d469f554ee6f85da4bc6f83c5fdd4b70b97e09161051f1fbe, mail.unitechautomations.com
vipkeylogger, 4b3fccf8e3e8cf25b5b63ba8f397687dd733fd884efe7c78083d154310f272e4, mail.sunrisefreight.com
vipkeylogger, 602e7534f0deeb7d99942cf865cbdd5602946728ec7487319c8ae9dd7f4e4eeb, server-624495.yupangco.com
vipkeylogger, 63e7fe8945be18dcd296c456a4a314d336c3c5c798d5c70066c02e7627861870, mail.taikei-rmc-co.biz
vipkeylogger, 6d36c8f8c2f52860b0172f656b6e96ecbc68f6fd4f51930c0c64935f67e334b5, mail.unitechautomations.com
vipkeylogger, 714e0f6fffc3b8adca5a1725319f8c8d086847e5e203ca2561c42fc55378bd8a, mail.taikei-rmc-co.biz
vipkeylogger, 8acc015652b5b580ffeeda6878751eaa3c412f1b34e856275efd42fd86851d0b, mail.unitechautomations.com
vipkeylogger, 8af7ef34bb470017a39d739fcb1a0be4f538783599e1f4cceaf7403ce262c71e, mail.sunrisefreight.com
vipkeylogger, c5e944d70372531124e32a0e9d12d9c6f5430e202bfa8ed9be027edf92d582ed, smtp.hostinger.com
vipkeylogger, e00a8580b10366c26edc801477b1f16e5d6619ea4692e862fbe4fe4adf26ddf0, https://api.telegram.org/bot8335324519
xloader, 0c82b648de097a84476eae0187e6ae187b4ec872a57cb2dd80aa2c5fdac05df3, www.malaro.site/zgoi
xloader, 0e5e342922cac7caf56c2934814bfbf99712b6342f7f07703712dd17da45fb6e, www.h19h9d.info/jam8
xloader, 16ff90b14867d9cde7cf8d405da63ea0c87f2c0cada7f00224d0099cb1a27d65, www.quyi-photo.com/du9u
xloader, 1ef388be81d3736c7f150e43658266540d0495b33c351dff18a328f5b8702039, www.johntorrens.org/wsl0
xloader, 25230a687002161160427e213dcdd2a17ae50d9b3ba9679916e238b55b61a6d2, www.87626985.xyz
xloader, 2e0055261615c13e5efadd2fb5137d62e24dd82cc0cc4a40e7f2ee759fdb85cb, www.gouttieresurmesure.fr
xloader, 351d3d2274389081c215d37dd5ac36e03594eb42123afb49fa5447e60f8156bd, www.malaro.site/zgoi
xloader, 3c7c35c4a683d2a074844e35dba1b716fb7409dfcee6a12113e32bbbeae8852a, www.ruayjangart.com
xloader, 46087fbb1844ba80157a958d0000075446f9cda7545c203720d073e7ec9dd62e, http://www.ervwyrdicmuvz.space/v9l6/
xloader, 479ca9e4974c18451cc33514037e524b1e04aea73d7ea1e2cec19ae5d443bb5d, http://www.aggroup.agency/iq85/
xloader, 5531654e84b8a3de3ce10423d12052f06db68e27805f874a1c4142bc27b0a37e, http://www.js194970.com/zt1q/
xloader, 6095802613f5bd7c2189dd74f5a473872f7671e174d512f5f30d6475081f37b4, www.malaro.site/zgoi
xloader, 6b15d702539c47fd54a63bda4d309e06d3c0b92d150f61c0b8b65eae787680be, www.malaro.site/zgoi
xloader, 706bd04b5489a253c4e35239df8e08b74f873dbfe8e5dfb3cfdd4a43491f9c62, www.030060272.xyz
xloader, 740117685e5ab345b8b786c7ee3127875dfea865c385ecb96296e9c2fad96dcb, www.legzocasino-ozz.online
xloader, 750d0ef6eaaac00190a10d38493cf765fcb9a9076ecf4d52ca356af4a650585f, www.radiancepurpose.com/iffy
xloader, 76caf765a683cb644927e208e4dba34f5f781c182c4e703ca0a1a2e4c70122e4, www.vintedbulk.com/qw57
xloader, 9b796f3ed25953c5f786a68211c50a08a630155949e36826ade8c91dd61b70b4, www.minute4cyber.cz/6qcn
xloader, a15bc7c686a5392d474006c52c2d1711a4aafeaef5f57c31d72d7709c14ac933, www.malaro.site/zgoi
xloader, a4ee12f9674be93285bebae1860592dbc2d4e9f0a1eb5f9d142a833c235f9af3, http://www.legzocasino-ozz.online/liqb/
xloader, a5b1465fbfb94c946d27f94d24159b4850aa4dd478abafaaa28b25bd06fa0f6a, https://www.reviewjournal.com/mpro
xloader, a70e389336554845cf466e5e921232974e9910c2572a89bbfb82a6417a3c431d, www.malaro.site/zgoi
xloader, a81497152c403cee17c51b92b6d337b080d19bb5b1105f563e42bbf7555c48cf, www.wojlpoe.buzz
xloader, b32d05c6d0606ae99980ac52e9acbae681e7c35936abca1aa7bbc66bc25bb0e5, http://www.otsumami-design.com/j6jq/
xloader, b9c3d1181ce23bba35e82fe27f2a1c3726f880e045be58ada8bf919c4b59375d, http://www.nvidias.in/b28p/
xloader, c516363e147f458e1806ace3348ded638bfdeef92c663a2478940e45b95cb911, www.ruayjangart.com
xloader, dfd829121ee37f87c27adf6bb11667417743d8622eb93330cdf0136e94506472, www.championspirit.kr
xloader, e6a5b93e3ff0565bfd8955d453a2ef89a8b7e5cc0687be73da77e8333c652178, http://www.thethinker.news/c6li/
xloader, fdc850a7bc3943be8fd89b9dcb5408cdd843729c195a3aa6c597d7a51f880aa8, www.legzocasino-ozz.online
xloader, fe0139a29474086a8352e614196fe8bb19f719678b61bbf99211e3d5a3894453, www.ponita.site/un5y
xworm, 0c04480d6f7b79530bad8c128795fe332cecbe146d2c0d83e475489ed9c9fd29, https://api.telegram.org/bot7409572452
xworm, 17b4b64cc0981196a5e53ef62d692b39af394ad5de609a76bb3d4dfb5efa979f, petro4prime.ydns.eu
xworm, 20beaec4ad8341161ef0a36de86a02923cb904d438823f86fd7dce0682429922, petro4prime.ydns.eu:5909
xworm, 403a3645736690384327ca4a8fa320a3d0a7cc16feabe7db7eb0206fdeb4fc9f, 185.208.159.254:3535
xworm, 4486326caba50ac9e71674d2fb0fdd4777e33132240a563f9c21c79d9d3f0368, 204.10.160.190:7003
xworm, 4b7857b0c84613d3132f968d6b0022a1cda6244fc425e0f2d5bdd79494cd6867, 31.40.204.103:1990
xworm, 50d3547eafa52153cc18ecea2f83c499a2811a95b8b8517d07502842a1bc1bd7, petro4prime.ydns.eu:5909
xworm, 6ad1b1db6f7c97ce50900ee4f898058f5ed4cb99bb7f63ce9b1f1509a3dd21e9, aaslooria.com:6000
xworm, 6e8bd59fdd70b7f37c446835847d317ebfffa1309ffc10091d751e80c6a7eb8f, xxblessings.minhaempresa.tv:1446
xworm, 787603ed370b21f4b0c042915f7fec0e3ad9f1a74f9bea21a99f9e7a5232a31c, petro4prime.ydns.eu:5909
xworm, a2932b3cc6e7a0c538c69b6b4b68b8fd82824f50adcc5567105fb844d846094b, 192.154.241.18:1960
xworm, b8c2e4d4a1946f273f3d178430ae78fe9dbeac19739cde22aa7dd1c1fdf95da1, 103.83.86.162:1985
xworm, c1631ae162f5eaefd7839ec215095dca0bab9bea585d74f93e5c61743cd662a4, petro4prime.ydns.eu:5909
xworm, ca212a7ee4e9f294e78a74a1b159006b72933d6408bab43f75c797ab1226b11c, evaultbuzzfix.com:6000
xworm, f5d384d10b94f31f151234b0bff7c4699e38883029727da32a2ccdef58b4589e, petro4prime.ydns.eu:5909
xworm, fea32668a5200cda959b27c6d39cb17e57136e41a9ffd717c12061be1bedc128, https://api.telegram.org/bot8245777519
xworm-originlogger, 0096d75048467d5a578ae590bc4a9451ae1a02f39de3a03546097baaf8e22399, 192.154.241.18:1960
ejima@aventour.com.mx
logs@htcp.homes
log@taikei-rmc-co.biz
mohammedddxxx@duct-master.com
pdls.sapountzis@transman.gr
zenda@eastsidedynamic.com
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment