Date Author Title
2024-01-03Jan KoprivaInteresting large and small malspam attachments from 2023
2023-06-29Brad DuncanGuLoader- or DBatLoader/ModiLoader-style infection for Remcos RAT
2023-05-30Brad DuncanMalspam pushes ModiLoader (DBatLoader) infection for Remcos RAT
2023-04-12Brad DuncanRecent IcedID (Bokbot) activity
2023-01-05Brad DuncanMore Brazil malspam pushing Astaroth (Guildma) in January 2023
2022-12-02Brad Duncanobama224 distribution Qakbot tries .vhd (virtual hard disk) images
2022-08-19Brad DuncanBrazil malspam pushes Astaroth (Guildma) malware
2022-07-07Brad DuncanEmotet infection with Cobalt Strike
2022-06-17Brad DuncanMalspam pushes Matanbuchus malware, leads to Cobalt Strike
2022-04-06Brad DuncanWindows MetaStealer Malware
2022-03-16Brad DuncanQakbot infection with Cobalt Strike and VNC activity
2021-12-31Jan KoprivaDo you want your Agent Tesla in the 300 MB or 8 kB package?
2021-12-22Brad DuncanDecember 2021 Forensic Contest: Answers and Analysis
2021-12-20Jan KoprivaPowerPoint attachments, Agent Tesla and code reuse in malware
2021-11-16Brad DuncanEmotet Returns
2021-10-22Brad DuncanOctober 2021 Contest: Forensic Challenge
2021-08-13Brad DuncanExample of Danabot distributed through malspam
2021-07-26Didier StevensFailed Malspam: Recovering The Password
2021-07-14Jan KoprivaOne way to fail at malspam - give recipients the wrong password for an encrypted attachment
2021-04-06Jan KoprivaMalspam with Lokibot vs. Outlook and RFCs
2021-02-24Brad DuncanMalspam pushes GuLoader for Remcos RAT
2021-02-17Brad DuncanMalspam pushing Trickbot gtag rob13
2021-01-20Brad DuncanQakbot activity resumes after holiday break
2021-01-13Brad DuncanHancitor activity resumes after a hoilday break
2020-12-09Brad DuncanRecent Qakbot (Qbot) activity
2020-10-14Brad DuncanMore TA551 (Shathak) Word docs push IcedID (Bokbot)
2020-08-07Brad DuncanTA551 (Shathak) Word docs push IcedID (Bokbot)
2020-07-10Brad DuncanExcel spreasheet macro kicks off Formbook infection
2020-06-10Brad DuncanJob application-themed malspam pushes ZLoader
2020-05-13Brad DuncanMalspam with links to zip archives pushes Dridex malware
2020-04-08Brad DuncanGerman malspam pushes ZLoader malware
2020-04-01Brad DuncanQakbot malspam sent from an infected Windows host
2020-03-25Brad DuncanRecent Dridex activity
2020-02-12Brad DuncanMalpsam pushes Ursnif through Italian language Word docs
2020-02-03Jan KoprivaAnalysis of a triple-encrypted AZORult downloader
2020-01-22Brad DuncanGerman language malspam pushes Ursnif
2020-01-16Jan KoprivaPicks of 2019 malware - the large, the small and the one full of null bytes
2019-12-18Brad DuncanEmotet infection with spambot activity
2019-12-11Brad DuncanGerman language malspam pushes yet another wave of Trickbot
2019-12-03Brad DuncanUrsnif infection with Dridex
2019-11-20Brad DuncanHancitor infection with Pony, Evil Pony, Ursnif, and Cobalt Strike
2019-11-13Brad DuncanAn example of malspam pushing Lokibot malware, November 2019
2019-11-06Brad DuncanMore malspam pushing Formbook
2019-10-02Brad DuncanA recent example of Emotet malspam
2019-09-25Brad DuncanMalspam pushing Quasar RAT
2019-09-18Brad DuncanEmotet malspam is back
2019-06-18Brad DuncanMalspam with password-protected Word docs pushing Dridex
2019-03-13Brad DuncanMalspam pushes Emotet with Qakbot as the follow-up malware
2019-03-06Brad DuncanMalspam with password-protected word docs still pushing IcedID (Bokbot) with Trickbot
2019-02-20Brad DuncanMore Russian language malspam pushing Shade (Troldesh) ransomware
2019-02-06Brad DuncanHancitor malspam and infection traffic from Tuesday 2019-02-05
2019-01-24Brad DuncanMalspam with Word docs uses macro to run Powershell script and steal system data
2019-01-16Brad DuncanEmotet infections and follow-up malware
2019-01-10Brad DuncanHeartbreaking Emails: "Love You" Malspam
2018-12-18Brad DuncanMalspam links to password-protected Word docs that push IcedID (Bokbot)
2018-12-05Brad DuncanCampaign evolution: Hancitor changes its Word macros
2018-12-04Brad DuncanMalspam pushing Lokibot malware
2018-11-29Brad DuncanRussian language malspam pushing Shade (Troldesh) ransomware
2018-11-15Brad DuncanEmotet infection with IcedID banking Trojan
2018-11-14Brad DuncanDay in the life of a researcher: Finding a wave of Trickbot malspam
2018-10-31Brad DuncanMore malspam using password-protected Word docs
2018-10-30Brad DuncanCampaign evolution: Hancitor malspam starts pushing Ursnif this week
2018-09-26Brad DuncanOne Emotet infection leads to three follow-up malware infections
2018-08-15Brad DuncanMore malspam pushing password-protected Word docs for AZORult and Hermes Ransomware
2018-08-02Brad DuncanDHL-themed malspam reveals embedded malware in animated gif
2018-07-27Brad DuncanMalspam with password-protected Word docs pushes Hermes ransomware
2018-07-24Brad DuncanRecent Emotet activity
2017-11-30Brad DuncanMore Malspam pushing Emotet malware
2017-10-19Brad DuncanHSBC-themed malspam uses ISO attachments to push Loki Bot malware
2017-10-17Brad DuncanHancitor malspam uses DDE attack
2017-09-18Xavier MertensGetting some intelligence from malspam
2017-09-01Brad DuncanMalspam pushing Locky ransomware tries HoeflerText notifications for Chrome and FireFox
2017-07-26Brad DuncanMalspam pushing Emotet malware
2017-07-14Brad DuncanNemucodAES and the malspam that distributes it
2017-06-28Brad DuncanCatching up with Blank Slate: a malspam campaign still going strong
2017-05-24Brad DuncanJaff ransomware gets a makeover
2017-04-11Brad DuncanDridex malspam seen on Monday 2017-04-10
2017-02-10Brad DuncanHancitor/Pony malspam