{"id":39390,"date":"2021-02-01T17:00:06","date_gmt":"2021-02-01T17:00:06","guid":{"rendered":"https:\/\/www.microsoft.com\/security\/blog\/?p=92767"},"modified":"2021-02-01T17:00:06","modified_gmt":"2021-02-01T17:00:06","slug":"what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/","title":{"rendered":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations"},"content":{"rendered":"<p>From March to December 2020, we tracked segments of a dynamically generated email infrastructure that attackers used to send more than a million emails per month, distributing at least seven distinct malware families in dozens of campaigns using a variety of phishing lures and tactics. These campaigns aimed to deploy malware on target networks across the world, with notable concentration in the United States, Australia,&nbsp;and the United Kingdom.&nbsp;Attackers targeted the wholesale distribution, financial services, and healthcare industries.<\/p>\n<p>By tracing these campaigns, we uncovered a sprawling infrastructure that is robust enough to seem legitimate to many mail providers, while flexible enough to allow the dynamic generation of new domain names and remain evasive. Shared IP space, domain generation algorithm (DGA) patterns, subdomains, registrations metadata, and signals from the headers of malicious emails enabled us to validate our research through overlaps in campaigns where attackers utilized multiple segments of purchased, owned, or compromised infrastructure. Using the intelligence we gathered on this infrastructure, we were at times able to predict how a domain was going to be used even before campaigns began.<\/p>\n<p>This email infrastructure and the malware campaigns that use it exemplify the increasing sophistication of cybercriminal operations, driven by attackers who are motivated to use malware infections for more damaging, potentially more lucrative attacks.&nbsp;In fact, more recent campaigns that utilized this infrastructure distributed malware families linked to&nbsp;follow-on&nbsp;<a href=\"https:\/\/www.microsoft.com\/security\/blog\/2020\/03\/05\/human-operated-ransomware-attacks-a-preventable-disaster\/\">human-operated attacks<\/a>, including campaigns that deployed Dopplepaymer, Makop, Clop, and other ransomware families.<\/p>\n<p>Our deep investigation into this infrastructure brings to light these important insights about persistent cybercriminal operations:<\/p>\n<ul>\n<li>Tracking an email infrastructure surfaces patterns in attacker activity, bubbling up common elements in seemingly disparate campaigns<\/li>\n<li>Among domains that attackers use for sending emails, distributing malware, or command-and-control, the email domains are the most likely to share basic registration similarities and more likely to use DGA<\/li>\n<li>Malware services rely on proxy providers to make tracking and attribution difficult, but the proxies themselves can provide insights into upcoming campaigns and improve our ability to proactively protect against them<\/li>\n<li>Gaining intelligence on email infrastructures enables us to build or improve proactive and comprehensive protections like those provided by Microsoft Defender for Office 365 to defend against some of the world\u2019s most active malware campaigns<\/li>\n<\/ul>\n<p>While there&nbsp;is&nbsp;existing in-depth research into&nbsp;some of these specific campaigns, in this blog we\u2019ll share more&nbsp;findings and&nbsp;details&nbsp;on how email distribution infrastructures drive some of the most prevalent malware operations today. Our goal is to provide&nbsp;important&nbsp;intelligence that hosting providers, registrars, ISPs, and email protection services can use&nbsp;and build on&nbsp;to protect customers from&nbsp;the threats of today and the future. We\u2019ll also share insights and context to empower security researchers and customers to take full advantage of solutions like <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/office-365-defender\">Microsoft Defender for Office 365<\/a> to perform deep investigation and hunting in their environment and make their organizations resilient against attacks.<\/p>\n<h2>The role of for-sale infrastructure services in the threat ecosystem<\/h2>\n<p>We spotted the first segment of the infrastructure in March, when multiple domains were registered using distinct naming patterns, including the heavy use of the word \u201cstrange\u201d, inspiring the name StrangeU. In April, a second segment of the infrastructure, one that used domain generation algorithm (DGA), began registration as well. We call this segment RandomU.<\/p>\n<p>The emergence of this infrastructure in March dovetailed with the disruption of the Necurs botnet that resulted in the reduction of service. Before being disrupted, Necurs was one of the world\u2019s largest botnets and was used by prolific malware campaign operators such as those behind Dridex. For-sale services like Necurs enable attackers to invest in malware production while leasing the delivery components of their activities to further obfuscate their behavior. The StrangeU and RandomU infrastructure appear to fill in the service gap that the Necurs disruption created, proving that attackers are highly motivated to quickly adapt to temporary interruptions to their operations.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-92776 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig1a-Timeline-of-staging-and-utilization.png\" alt=\"Graph showing timeline of the Necurs takedown and the staging and operation of StrangeU and RandomU\" width=\"993\" height=\"380\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig1a-Timeline-of-staging-and-utilization.png 993w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig1a-Timeline-of-staging-and-utilization-300x115.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig1a-Timeline-of-staging-and-utilization-768x294.png 768w\" sizes=\"auto, (max-width: 993px) 100vw, 993px\"><\/p>\n<p><em>Figure 1. Timeline of staging and utilization of the email infrastructure <\/em><\/p>\n<p>At first, the new email infrastructure was used infrequently in campaigns that distributed highly commodity malware like Mondfoxia and Makop. Soon, however, it attracted the attention of Dridex and Trickbot operators, who began using the infrastructure for portions of their campaigns, sometimes entirely and sometimes mixed with other compromised infrastructure or email providers.<\/p>\n<p>Analyzing these mail clusters provides insight into how human the tangled web of modular attacker infrastructure remains. From unifying key traits in registration and behavior to the simple and effective techniques that the wide variety of malware uses, attackers\u2019 goals in this diversification point toward combatting automated analysis. However, these same shared characteristics and methods translate to insights that inform resilient protections that defend customers against these attacks.<\/p>\n<h2>Domain registration and email infrastructure staging<\/h2>\n<p>On March 7, 2020,&nbsp;attackers began registering a series of domains with Namecheap&nbsp;using&nbsp;sets of stolen email addresses, largely from free email services like mail.com, mail.ru, list.ru, and others. These domains all had similar characteristics that&nbsp;could&nbsp;be linked back to various similarities in registration. Almost all&nbsp;of the registered domains&nbsp;contained the word \u201cstrange\u201d and&nbsp;were under&nbsp;the&nbsp;<em>.us<\/em>&nbsp;TLD, hence the name StrangeU.&nbsp;The use of&nbsp;<em>.us<\/em>&nbsp;TLD&nbsp;prevented domain or&nbsp;WHOIS&nbsp;privacy&nbsp;services\u2014often used to obfuscate&nbsp;domain&nbsp;ownership and provenance\u2014which&nbsp;are&nbsp;prohibited&nbsp;for this&nbsp;TLD.<\/p>\n<p>To circumvent&nbsp;tracking and&nbsp;detection&nbsp;of these domains,&nbsp;attackers used false registration metadata. However,&nbsp;there was&nbsp;heavy&nbsp;crossover in&nbsp;the&nbsp;fake&nbsp;names and&nbsp;email&nbsp;addresses,&nbsp;allowing&nbsp;us&nbsp;to find additional&nbsp;domain&nbsp;names,&nbsp;some of which could be tied together using other&nbsp;keywords&nbsp;as shown&nbsp;in the list&nbsp;below, and fingerprint the domain generation mechanism.<\/p>\n<p>The StrangeU domains were registered in&nbsp;early March&nbsp;2020 and operated in continuous small bursts until April, when they were used for a large ransomware campaign. Following that, a new campaign occurred fairly regularly every few weeks. Registration of new domains continued throughout the year, and in September, the StrangeU infrastructure was used in conjunction with a similar infrastructure to deliver Dridex, after which these domains were used less frequently.<\/p>\n<p>This second mailing segment, RandomU, employed a different DGA mechanism but still utilized Namecheap and showed a more consistent through line of registration metadata than its StrangeU counterpart. This infrastructure, which surfaced in April, was used infrequently through the Spring, with a surge in May and July. After the Dridex campaign in September in which it was used along with StrangeU, it has been used in two large Dridex campaigns every month.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-92770 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig2-common-patterns.png\" alt=\"Table listing observed patterns in StrangeU and RandomU infrastructures\" width=\"720\" height=\"376\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig2-common-patterns.png 720w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig2-common-patterns-300x157.png 300w\" sizes=\"auto, (max-width: 720px) 100vw, 720px\"><\/p>\n<p><em>Figure 2. Common patterns in domains belonging to the email infrastructure<\/em><\/p>\n<p>The StrangeU and RandomU segments of domains paint a picture of supplementing modular mailing services that allowed attackers to launch region-specific and enterprise-targeting attacks at scale, delivering over six million emails. The two segments contained a standard barrage of mailing subdomains, with over 60 unique subdomains referencing email across clusters, consistent with each other, with each domain having four to five subdomains. The following is a sample of malware campaigns, some of which we discuss in detail in succeeding sections, that we observed this infrastructure was used for:<\/p>\n<ul>\n<li>Korean&nbsp;spear-phishing&nbsp;campaigns&nbsp;that delivered&nbsp;Makop ransomware&nbsp;in&nbsp;April&nbsp;and&nbsp;June<\/li>\n<li>Emergency alert notifications&nbsp;that distributed&nbsp;Mondfoxia&nbsp;in&nbsp;April<\/li>\n<li>Black Lives Matter lure&nbsp;that&nbsp;delivered&nbsp;Trickbot&nbsp;in&nbsp;June<\/li>\n<li>Dridex&nbsp;campaign delivered through&nbsp;StrangeU&nbsp;and other infra from&nbsp;June to July<\/li>\n<li>Dofoil&nbsp;(SmokeLoader)&nbsp;campaign in August<\/li>\n<li>Emotet and Dridex activities&nbsp;in September, October, and November<\/li>\n<\/ul>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-92771 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig3-Timeline-of-campaigns.png\" alt=\"Timeline of campaigns using the StrangeU and RandomU infrastructures\" width=\"975\" height=\"347\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig3-Timeline-of-campaigns.png 975w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig3-Timeline-of-campaigns-300x107.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig3-Timeline-of-campaigns-768x273.png 768w\" sizes=\"auto, (max-width: 975px) 100vw, 975px\"><\/p>\n<p><em>Figure 3. Timeline of campaigns that used StrangeU and RandomU domains<\/em><\/p>\n<h2>Korean spear-phishing delivers Makop ransomware (April and June 2020)<\/h2>\n<p>In early April, StrangeU was used&nbsp;to&nbsp;deliver&nbsp;the Makop ransomware.&nbsp;The emails&nbsp;were sent to organizations&nbsp;that had major business operations in&nbsp;Korea&nbsp;and&nbsp;used&nbsp;names of Korean companies as display names.&nbsp;Signals from&nbsp;Microsoft Defender for Office 365&nbsp;indicated that these campaigns ran&nbsp;in short bursts.<\/p>\n<p>The emails&nbsp;had&nbsp;<em>.zip<\/em>&nbsp;attachments&nbsp;containing executables with file names&nbsp;that resembled&nbsp;resumes&nbsp;from job seekers. Once&nbsp;a&nbsp;user opened the&nbsp;attachments,&nbsp;the executables&nbsp;delivered&nbsp;Makop, a&nbsp;ransomware-as-a-service&nbsp;(RaaS)&nbsp;payload that&nbsp;targeted&nbsp;devices and backups.<\/p>\n<p>Upon infection,&nbsp;the malware&nbsp;quickly&nbsp;used&nbsp;the&nbsp;WMI command-line (WMIC) utility&nbsp;and&nbsp;deleted&nbsp;shadow copies. It then used&nbsp;the&nbsp;BCEdit&nbsp;tool&nbsp;and&nbsp;altered the&nbsp;boot configuration to ignore future failures and prevent restoration before encrypting all files&nbsp;and renaming them&nbsp;with&nbsp;<em>.makop<\/em>&nbsp;extensions.<\/p>\n<p>The second time we observed the campaign almost two months later, in early June, the attackers used a Makop ransomware variant with many modified elements, including added persistence via scripts&nbsp;in the&nbsp;<em>Startup<\/em>&nbsp;folder&nbsp;before triggering&nbsp;a reboot.<\/p>\n<p>Nearly&nbsp;identical&nbsp;attempts to deliver&nbsp;Makop&nbsp;using&nbsp;resume-based&nbsp;lures&nbsp;were&nbsp;covered by&nbsp;Korean security media&nbsp;during the entire&nbsp;year, using popular mail services through legitimate vendors like Naver and Hanmail. This could indicate that during short bursts the Makop operators were unable to launch their campaigns through legitimate services and had to move to alternate infrastructures like StrangeU instead.<\/p>\n<h2>Black Lives Matter lure delivers Trickbot (June 2020)<\/h2>\n<p>One campaign&nbsp;associated with&nbsp;the&nbsp;StrangeU&nbsp;infrastructure&nbsp;gained notoriety&nbsp;in mid-June for its lure as well as for delivering the notorious info-stealing malware Trickbot. This campaign circulated emails&nbsp;with malicious Word documents&nbsp;claiming to seek anonymous input on the Black Lives Matter movement.<\/p>\n<p>An initial version of this campaign was observed on&nbsp;June 10 sending&nbsp;emails from&nbsp;a separate,&nbsp;unique attacker-owned mailing infrastructure&nbsp;using <em>.monster<\/em>&nbsp;domains.&nbsp;However, in the&nbsp;next&nbsp;iteration almost two weeks later, the campaign delivered emails from various domains specifically created with the Black Lives Matter signage, interspersed with StrangeU domains:<\/p>\n<ul>\n<li>b-lives-matter[.]site<\/li>\n<li>blivesm[.]space<\/li>\n<li>blivesmatter[.]site<\/li>\n<li>lives-matter-b[.]xyz<\/li>\n<li>whoslivesmatter[.]site<\/li>\n<li>lives-m-b[.]xyz<\/li>\n<li>ereceivedsstrangesecureworld[.]us<\/li>\n<li>b-l-m[.]site<\/li>\n<\/ul>\n<p>Both campaigns carried the&nbsp;same Trickbot payload, operated for two days, and used identical post-execution commands and callouts to compromised WordPress sites.<\/p>\n<p>Once&nbsp;a&nbsp;user opened&nbsp;the document attachment and enabled the malicious macro, Word launched <em>cmd.exe<\/em> with the command \u201c<em>\/c pause<\/em>\u201d&nbsp;to evade security&nbsp;tools that&nbsp;monitored&nbsp;for&nbsp;successive launches of multiple processes.&nbsp;It then&nbsp;launched commands that&nbsp;deleted&nbsp;proxy settings in&nbsp;preparation for connecting to&nbsp;multiple&nbsp;C2&nbsp;IP&nbsp;addresses.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-92772\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig4-Malicious-document-trickbot.png\" alt=\"Screenshot of malicious document\" width=\"500\" height=\"375\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig4-Malicious-document-trickbot.png 1100w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig4-Malicious-document-trickbot-300x225.png 300w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig4-Malicious-document-trickbot-1024x768.png 1024w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig4-Malicious-document-trickbot-768x576.png 768w\" sizes=\"auto, (max-width: 500px) 100vw, 500px\"><\/p>\n<p><em>Figure 4. Screenshot of the malicious document used to deliver Trickbot<\/em><\/p>\n<p>The&nbsp;commands also&nbsp;launched&nbsp;<em>rundll32.exe<\/em>,&nbsp;a native binary commonly used as a&nbsp;<a href=\"https:\/\/securitycenter.microsoft.com\/threatanalytics3\/96666263-eb70-4b24-b2e7-c8b39822101f\">living-off-the-land binary<\/a>,&nbsp;to&nbsp;load a malicious file in memory.&nbsp;The commandeered&nbsp;<em>rundll32.exe <\/em>also<em>&nbsp;<\/em>proceeded to perform other tasks using&nbsp;other living-off-the-land binaries, including&nbsp;<em>wermgr.exe<\/em>&nbsp;and&nbsp;<em>svchost.exe<\/em>.<\/p>\n<p>In turn, the&nbsp;hijacked&nbsp;<em>wermgr.exe<\/em>&nbsp;process&nbsp;dropped&nbsp;a file with a <em>.dog<\/em> extension that appeared to be the Trickbot&nbsp;payload.&nbsp;The same instance of&nbsp;<em>wermgr.exe<\/em>&nbsp;then&nbsp;appeared to&nbsp;inject&nbsp;code&nbsp;into&nbsp;<em>svchost.exe<\/em>&nbsp;and scanned&nbsp;for&nbsp;open SMB ports on other&nbsp;devices.&nbsp;The&nbsp;commandeered<em>&nbsp;svchost.exe<\/em>&nbsp;used&nbsp;WMI to open connections to additional devices on the network,&nbsp;while continuing to collect data from the initial infected&nbsp;device.&nbsp;It&nbsp;also&nbsp;opened&nbsp;multiple browsers on localhost connections to capture browser history and other information via&nbsp;<em>esentutl.exe<\/em>&nbsp;and&nbsp;<em>grabber_temp.edb<\/em>,&nbsp;both of&nbsp;which&nbsp;are&nbsp;often&nbsp;used by&nbsp;the&nbsp;Trickbot&nbsp;malware family.<\/p>\n<p>This campaign overwhelmingly targeted&nbsp;corporate accounts&nbsp;in&nbsp;the United States and&nbsp;Canada&nbsp;and avoided&nbsp;individual accounts. Despite heavy media coverage, this campaign was&nbsp;relatively&nbsp;small, reflecting&nbsp;a common&nbsp;behavior among cybercrime groups, which often run multiple, dynamic low-volume campaigns&nbsp;designed to&nbsp;evade resilient detection.<\/p>\n<h2>Dridex&nbsp;campaigns big and small (June to July 2020 and beyond)<\/h2>\n<p>From late June through July, Dridex operators ran numerous campaigns that distributed Excel documents with malicious macros to infect devices.&nbsp;These operators first delivered emails through the <em>StrangeU<\/em> infrastructure only, but they quickly started to use compromised email accounts of legitimate organizations as well, preventing defenders from easily blocking deliveries. Despite this, emails from either&nbsp;<em>StrangeU<\/em>&nbsp;or the compromised accounts had overlapping attributes. For example, many of the emails used the same&nbsp;<em>Reply<\/em> <em>To<\/em>&nbsp;addresses that were sourced from compromised individual accounts and not consistent with the sender addresses.<\/p>\n<p>During the bulk of this run, Excel files were attached directly in the email in order to eventually pull the&nbsp;Dridex&nbsp;payload from .xyz&nbsp;domains such as those below. The attackers changed the delivery domains every few days and connected to IP-based C2s on familiar ports like 4664, 3889, 691, and 8443:<\/p>\n<ul>\n<li>yumicha[.]xyz<\/li>\n<li>rocesi[.]xyz<\/li>\n<li>secretpath[.]xyz<\/li>\n<li>guruofbullet[.]xyz<\/li>\n<li>Greyzone[.]xyz<\/li>\n<\/ul>\n<p>When opened, the Excel document installed one of a series of custom&nbsp;Dridex&nbsp;executables downloaded from the attacker C2 sites. Like most variants in this malware family, the custom&nbsp;Dridex&nbsp;executables incorporated code loops, time delays, and environment detection mechanisms that evaded numerous public and enterprise sandboxes.<\/p>\n<p>Dridex&nbsp;is known for its capability to perform credential theft and establish connectivity to attacker infrastructure. In this instance, the same&nbsp;Dridex&nbsp;payload was circulated daily using varying lures, often repeatedly to the same organizations to ensure execution on target networks.<\/p>\n<p>During the longer and more stable Excel&nbsp;Dridex&nbsp;campaigns in June and July, a Dridex variant was also distributed in much smaller quantities utilizing Word documents over a one-day period, perhaps&nbsp;testing new evasion techniques. These Word documents, while still delivering&nbsp;Dridex, improved existing obfuscation methods using a unique combination of VBA stomping and replacing macros and function calls with arbitrary text. In a few samples of these documents, we found text from Shakespearean prose.<\/p>\n<pre>&lt;\/ms:script&gt;&nbsp;&nbsp;&nbsp;\nvar farewell_and_moon = [\"m\",\"a\",\"e\",\"r\",\"t\",\"s\",\".\",\"b\",\"d\",\"o\",\"d\",\"a\"].reverse().join(\"\")\u202f\u202f&nbsp;\na_painted_word(120888)\u202f\u202f&nbsp;\nfunction as_thy_face(takes_from_hamlet)\u202f\u202f&nbsp;\n{return new ActiveXObject(takes_from_hamlet)}\u202f\u202f&nbsp;\n&lt;\/ms:script&gt;<\/pre>\n<p>While Microsoft researchers&nbsp;didn\u2019t&nbsp;observe this portion of the campaign moving into the human-operated phase\u2014targets did not open the attachment\u2014this campaign was likely to introduce tools like PowerShell Empire or Cobalt Strike to steal credentials, move laterally, and deploy ransomware.<\/p>\n<h2>Emotet,&nbsp;Dridex,&nbsp;and&nbsp;the RandomU infrastructure (September and&nbsp;beyond)<\/h2>\n<p>Despite an errant handful of deliveries distributing Dofoil (also known as SmokeLoader) and other malware, the vast majority of the remaining deliveries through StrangeU have been Dridex campaigns that reoccured every few weeks for a handful of days at a time. These campaigns started on September 7, when RandomU and StrangeU were notably used in a single campaign, after which StrangeU began to see less utilization.<\/p>\n<p>These Dridex campaigns utilized an Emotet loader and initial infrastructure for hosting, allowing the attackers to conduct a&nbsp;highly modular email campaign that delivered multiple distinct links to compromised domains. These domains employed&nbsp;heavy sandbox evasion and are&nbsp;connected by a series of PHP patterns&nbsp;ending in a small subset of options:&nbsp;<em>zxlbw.php<\/em>,&nbsp;<em>yymclv.php<\/em>,&nbsp;<em>zpsxxla.php<\/em>, or&nbsp;<em>app.php<\/em>. As the campaigns continued, the PHP was dynamically generated, adding other variants, including <em>vary.php<\/em>, <em>invoice.php<\/em>, <em>share.php<\/em>, and many others. Some examples are below.<\/p>\n<ul>\n<li>hxxps:\/\/molinolafama[.]com[.]mx\/app[.]php<\/li>\n<li>hxxps:\/\/meetingmins[.]com\/app[.]php<\/li>\n<li>hxxps:\/\/contrastmktg[.]com\/yymclv[.]php<\/li>\n<li>hxxps:\/\/idklearningcentre[.]com[.]ng\/zxlbw[.]php<\/li>\n<li>hxxps:\/\/idklearningcentre[.]com[.]ng\/zpsxxla[.]php<\/li>\n<li>hxxps:\/\/idklearningcentre[.]com[.]ng\/yymclv[.]php<\/li>\n<li>hxxps:\/\/hsa[.]ht\/yymclv[.]php<\/li>\n<li>hxxps:\/\/hsa[.]ht\/zpsxxla[.]php<\/li>\n<li>hxxps:\/\/hsa[.]ht\/zxlbw[.]php<\/li>\n<li>hxxps:\/\/contrastmktg[.]com\/yymclv[.]php<\/li>\n<li>hxxps:\/\/track[.]topad[.]co[.]uk\/zpsxxla[.]php<\/li>\n<li>hxxps:\/\/seoemail[.]com[.]au\/zxlbw[.]php<\/li>\n<li>hxxps:\/\/bred[.]fr-authentification-source-no[.]inaslimitada[.]com\/zpsxxla[.]php<\/li>\n<li>hxxp:\/\/www[.]gbrecords[.]london\/zpsxxla[.]php<\/li>\n<li>hxxp:\/\/autoblogsite[.]com\/zpsxxla[.]php<\/li>\n<li>hxxps:\/\/thecrossfithandbook[.]com\/zpsxxla[.]php<\/li>\n<li>hxxps:\/\/mail[.]168vitheyrealestate[.]com\/zpsxxla[.]php<\/li>\n<\/ul>\n<p>In this campaign, sandboxes&nbsp;were frequently redirected to unrelated sites&nbsp;like&nbsp;chemical manufacturers or medical suppliers,&nbsp;while users received an&nbsp;Emotet&nbsp;downloader within a&nbsp;Word&nbsp;document, which&nbsp;once again used&nbsp;macros&nbsp;to&nbsp;facilitate malicious activities.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone wp-image-92773 size-full\" src=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig5-document-Dridex.png\" alt=\"Screenshot of malicious document\" width=\"481\" height=\"144\" srcset=\"https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig5-document-Dridex.png 481w, https:\/\/www.microsoft.com\/security\/blog\/wp-content\/uploads\/2021\/02\/Fig5-document-Dridex-300x90.png 300w\" sizes=\"auto, (max-width: 481px) 100vw, 481px\"><\/p>\n<p><em>Figure 5. Screenshot of the malicious document used to deliver Dridex<\/em><\/p>\n<p>The malicious macro utilized WMI to run a series of standard PowerShell commands. First, it downloaded the executable payload itself by contacting a series of C2 domains associated with Emotet campaigns since July. Afterward, additional encoded PowerShell commands were used in a similar fashion to download a .zip file that contained a Dridex DLL. Additional commands also reached out to a variety of Emotet infrastructure hosted on compromised WordPress administrative pages, even after the Dridex payload has already been downloaded. Dridex then modified RUN keys to automatically start the Dridex executable, which was renamed to riched20.exe on subsequent logons.<\/p>\n<p>We&nbsp;also&nbsp;observed simultaneous connections to&nbsp;associated&nbsp;Dridex&nbsp;and&nbsp;Emotet&nbsp;infrastructure. These connections&nbsp;were largely unencrypted and&nbsp;occurred&nbsp;over a variety of ports and services, including&nbsp;ports 4664 and 9443.&nbsp;At&nbsp;this&nbsp;point the malware had&nbsp;firm&nbsp;presence on the machine, enabling attackers to&nbsp;perform&nbsp;human-operated activity at a later date.<\/p>\n<p>In the past,&nbsp;reports have&nbsp;confirmed Dridex&nbsp;being delivered via leased&nbsp;Emotet&nbsp;infrastructure. There have also been many&nbsp;IP and&nbsp;payload-based associations. This research adds to that body of&nbsp;work and confirms additional associations&nbsp;via namespace, as well as correlation of&nbsp;email lure, metadata,&nbsp;and sender. This iteration of campaign repeated through October to December largely unchanged with nearly identical mails.<\/p>\n<h2>Defending organizations against malware campaigns<\/h2>\n<p>As attacks continue to grow in modularity, the tactics that attackers use to deliver phishing email, gain initial access on systems, and move laterally will continuously become more varied. This research shows that despite these disparities and the increased resiliency attackers have built, the core tactics and tools that they use are still limited in scope, relying repeatedly on familiar malicious macros, lures, and sending tactics.<\/p>\n<p>Sweeping research into massive attacker infrastructures, as well as our real-time monitoring of malware campaigns and attacker activity, directly inform Microsoft security solutions, allowing us to build or improve protections that block malware campaigns and other email threats, both current and future, as well as provide enterprises with the tools for investigating and responding to email campaigns in real-time.<\/p>\n<p>Microsoft delivers these capabilities through <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/office-365-defender\">Microsoft Defender for Office 365<\/a>. Features likes <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/atp-safe-attachments\">Safe attachments<\/a> and <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/atp-safe-links\">Safe links<\/a> ensure real-time, dynamic protection against email campaigns no matter the lure or evasion tactic. These features use a combination of detonation, automated analysis, and machine learning to detect new and unknown threats. Meanwhile, the <a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/campaigns\">Campaign view<\/a> shows the complete picture of email campaigns as they happen, including timelines, sending patterns, impact to the organization, and details like IP addresses, senders, and URLs. These insights into email threats empower security operations teams to respond to attacks, perform additional hunting, and fix configuration issues.<\/p>\n<p>Armed with an advanced solution like Microsoft Defender for Office 365 and the rest of technologies in the broader <a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/microsoft-365-defender\">Microsoft 365 Defender<\/a> solution, enterprises can further increase resilience against threats by following these recommendations:<\/p>\n<ul>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/attack-simulator?view=o365-worldwide\">Educate end users<\/a> about protecting personal and business information in social media, filtering unsolicited communication, identifying lures in spear-phishing email, and reporting of reconnaissance attempts and other suspicious activity.<\/li>\n<li><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/recommended-settings-for-eop-and-office365-atp?view=o365-worldwide\">Configure <\/a><a href=\"https:\/\/docs.microsoft.com\/en-us\/microsoft-365\/security\/office-365-security\/recommended-settings-for-eop-and-office365-atp\">Office 365 email filtering settings<\/a> to ensure blocking of phishing &amp; spoofed emails, spam, and emails with malware. Set Office 365 to&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/office365\/securitycompliance\/atp-safe-links\">recheck links on click<\/a> and&nbsp;<a href=\"https:\/\/docs.microsoft.com\/en-us\/office365\/securitycompliance\/zero-hour-auto-purge\">delete sent mail<\/a>&nbsp;to benefit from newly acquired threat intelligence.<\/li>\n<li>Disallow macros or allow only macros from trusted locations. See the&nbsp;latest\u202f<a href=\"https:\/\/blogs.technet.microsoft.com\/secguide\/2018\/02\/13\/security-baseline-for-office-2016-and-office-365-proplus-apps-final\/\">security baselines for Office and Office 365<\/a>.<\/li>\n<li>Turn on <a href=\"https:\/\/cloudblogs.microsoft.com\/microsoftsecure\/2018\/09\/12\/office-vba-amsi-parting-the-veil-on-malicious-macros\/\">AMSI for Office VBA<\/a>.<\/li>\n<li>Check perimeter firewall and proxy to restrict servers from making arbitrary connections to the internet to browse or download files. Turn on <a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/microsoft-defender-atp\/enable-network-protection\">network protection<\/a> to block connections to malicious domains and IP addresses. Such restrictions help inhibit malware downloads and command-and-control activity.<\/li>\n<\/ul>\n<p>Turning&nbsp;on\u202f<a href=\"https:\/\/docs.microsoft.com\/en-us\/windows\/security\/threat-protection\/windows-defender-exploit-guard\/attack-surface-reduction-exploit-guard\">attack surface reduction rules<\/a>, including&nbsp;rules that can block advanced macro activity, executable content, process creation, and process injection initiated by Office applications, also significantly improves defenses. The following rules are especially useful in blocking the techniques observed in campaigns using the StrangeU and RandomU infrastructure:<\/p>\n<p>Microsoft 365 customers can also use the advanced hunting capabilities in Microsoft 365 Defender, which integrates signals from Microsoft Defender for Office 365 and other solutions, to locate activities and artifacts related to the infrastructure and campaigns discussed in this blog. These queries can be used with advanced hunting in Microsoft 365 security center, but the same regex pattern can be used on other security tools to identify or block emails.<strong><em> \u202f<\/em><\/strong><\/p>\n<p>This query searches&nbsp;for&nbsp;emails sent&nbsp;from&nbsp;<em>StrangeU<\/em><strong><em>\u202f<\/em><\/strong><em>e<\/em>mail addresses.&nbsp;<a href=\"https:\/\/security.microsoft.com\/hunting?query=H4sIAAAAAAAEAO1Ru07DQBCcGol_sBAFoSA9DRSELhIS0CEk4wexFOxwZwJI_nhm55bYkJ4Kne5uH7ezM7dzzLHAC3I0WCMi467QoqdVI6BjLsMt_cA3LZ6ZvWfkuyLjXXIFxqNqDeNE_ive-CZ4bEm7EGLkrtXhDivlc3k3yvb0C54N7RYzxjMc4mDCcoGtc4yeG3i_E6sSmvG1fCl_6VXXruZKp8Va19Gz38pZWr1p_KB9iSM8UssFzoWUU0_k68H7bIj6SW9qp0zB3Yhl6fn9yBQtOt9BrLa8x0i10_1E5t2uptMP5OwaFRvnM4iPqd3Qrv3Pp1UJP7CTzSRxn-EMp1T7Gyuqy4i8zyZVPvA0Rcf8tTSVjjg_Z_E_g7-bwRd6XB5c2gMAAA&amp;runQuery=true&amp;timeRangeId=month\">Run query<\/a><\/p>\n<pre>EmailEvents\u202f\u202f&nbsp;\n|\u202fwhere\u202fSenderMailFromDomain\u202fmatches regex\u202f@\"^(?:eraust|ereply|reply|ereceived|received|reaust|esend|inv|send|emailboost|eontaysstrange|eprop|frost|eont|servicply).*(strange|stange|emailboost).*\\.us$\"\u202f\u202f or\u202fSenderFromDomain\u202fmatches regex\u202f@\"^(?:eraust|ereply|reply|ereceived|received|reaust|esend|inv|send|emailboost|eontaysstrange|eprop|frost|eont|servicply).*(strange|stange|emailboost).*\\.us$\"<\/pre>\n<p><a href=\"https:\/\/www.microsoft.com\/en-us\/microsoft-365\/security\/microsoft-365-defender\">Learn how you can stop attacks through automated, cross-domain security and built-in AI with Microsoft Defender 365<\/a>.<\/p>\n<h2>Indicators of compromise<\/h2>\n<h3>StrangeU domains<\/h3>\n<table>\n<tbody>\n<tr>\n<td width=\"208\">esendsstrangeasia[.]us<\/td>\n<td width=\"208\">sendsstrangesecuretoday[.]us<\/td>\n<td width=\"208\">emailboostgedigital[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">emailboostgelife[.]us<\/td>\n<td width=\"208\">emailboostgelifes[.]us<\/td>\n<td width=\"208\">emailboostgesecureasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">eontaysstrangeasia[.]us<\/td>\n<td width=\"208\">eontaysstrangenetwork[.]us<\/td>\n<td width=\"208\">eontaysstrangerocks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">eontaysstrangesecureasia[.]us<\/td>\n<td width=\"208\">epropivedsstrangevip[.]us<\/td>\n<td width=\"208\">ereplyggstangeasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplyggstangedigital[.]us<\/td>\n<td width=\"208\">ereplyggstangeereplys[.]us<\/td>\n<td width=\"208\">ereplyggstangelifes[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplyggstangenetwork[.]us<\/td>\n<td width=\"208\">ereplyggstangesecureasia[.]us<\/td>\n<td width=\"208\">frostsstrangeworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">servicceivedsstrangevip[.]us<\/td>\n<td width=\"208\">servicplysstrangeasia[.]us<\/td>\n<td width=\"208\">servicplysstrangedigital[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">servicplysstrangelife[.]us<\/td>\n<td width=\"208\">servicplysstrangelifes[.]us<\/td>\n<td width=\"208\">servicplysstrangenetwork[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangesecureworld[.]us<\/td>\n<td width=\"208\">ereceivedsstrangetoday[.]us<\/td>\n<td width=\"208\">ereceivedsstrangeus[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">esendsstrangesecurelife[.]us<\/td>\n<td width=\"208\">sendsstrangesecureesendss[.]us<\/td>\n<td width=\"208\">ereplysstrangesecureasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangesecurenetwork[.]us<\/td>\n<td width=\"208\">receivedsstrangesecurelife[.]us<\/td>\n<td width=\"208\">ereplysstrangeworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">reauestysstrangesecurelive[.]us<\/td>\n<td width=\"208\">ereceivedsstrangeworld[.]us<\/td>\n<td width=\"208\">esendsstrangesecurerocks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">reauestysstrangesecuredigital[.]us<\/td>\n<td width=\"208\">reauestysstrangesecurenetwork[.]us<\/td>\n<td width=\"208\">reauestysstrangesecurevip[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangesecurelife[.]us<\/td>\n<td width=\"208\">ereauestysstrangesecurerocks[.]us<\/td>\n<td width=\"208\">ereceivedsstrangeasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangedigital[.]us<\/td>\n<td width=\"208\">ereceivedsstrangeereceiveds[.]us<\/td>\n<td width=\"208\">ereceivedsstrangelife[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangelifes[.]us<\/td>\n<td width=\"208\">ereceivedsstrangenetwork[.]us<\/td>\n<td width=\"208\">ereceivedsstrangerocks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangesecureasia[.]us<\/td>\n<td width=\"208\">receivedsstrangeworld[.]us<\/td>\n<td width=\"208\">replysstrangedigital[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">invdeliverynows[.]us<\/td>\n<td width=\"208\">esendsstrangesecuredigital[.]us<\/td>\n<td width=\"208\">esendsstrangesecureworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sendsstrangesecurenetwork[.]us<\/td>\n<td width=\"208\">ereceivedsstrangevip[.]us<\/td>\n<td width=\"208\">replysstrangerocs[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangesecurelive[.]us<\/td>\n<td width=\"208\">invpaymentnoweros[.]us<\/td>\n<td width=\"208\">invpaymentnowes[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangeracs[.]us<\/td>\n<td width=\"208\">reauestysstrangesecurebest[.]us<\/td>\n<td width=\"208\">receivedsstrangesecurebest[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">reauestysstrangesecurelife[.]us<\/td>\n<td width=\"208\">ereplysstrangevip[.]us<\/td>\n<td width=\"208\">reauestysstrangesecuretoday[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangesecureus[.]us<\/td>\n<td width=\"208\">ereplysstrangetoday[.]us<\/td>\n<td width=\"208\">ereceivedsstrangesecuredigital[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangesecureereceiveds[.]us<\/td>\n<td width=\"208\">ereceivedsstrangesecurelife[.]us<\/td>\n<td width=\"208\">ereceivedsstrangesecurenetwork[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedsstrangesecurerocks[.]us<\/td>\n<td width=\"208\">ereceivedsstrangesecureus[.]us<\/td>\n<td width=\"208\">ereceivedsstrangesecurevip[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sendsstrangesecurebest[.]us<\/td>\n<td width=\"208\">sendsstrangesecuredigital[.]us<\/td>\n<td width=\"208\">sendsstrangesecurelive[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sendsstrangesecureworld[.]us<\/td>\n<td width=\"208\">esendsstrangedigital[.]us<\/td>\n<td width=\"208\">esendsstrangeesends[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">esendsstrangelifes[.]us<\/td>\n<td width=\"208\">esendsstrangerocks[.]us<\/td>\n<td width=\"208\">esendsstrangesecureasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">esendsstrangesecureesends[.]us<\/td>\n<td width=\"208\">esendsstrangesecurenetwork[.]us<\/td>\n<td width=\"208\">esendsstrangesecureus[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">esendsstrangesecurevip[.]us<\/td>\n<td width=\"208\">esendsstrangevip[.]us<\/td>\n<td width=\"208\">ereauestysstrangesecureasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangeasia[.]us<\/td>\n<td width=\"208\">ereplysstrangedigital[.]us<\/td>\n<td width=\"208\">ereplysstrangeereplys[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangelife[.]us<\/td>\n<td width=\"208\">ereplysstrangelifes[.]us<\/td>\n<td width=\"208\">ereplysstrangenetwork[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangerocks[.]us<\/td>\n<td width=\"208\">ereplysstrangesecuredigital[.]us<\/td>\n<td width=\"208\">ereplysstrangesecureereplys[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangesecurelife[.]us<\/td>\n<td width=\"208\">ereplysstrangesecurerocks[.]us<\/td>\n<td width=\"208\">ereplysstrangesecurevip[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplysstrangesecureworld[.]us<\/td>\n<td width=\"208\">ereplysstrangeus[.]us<\/td>\n<td width=\"208\">reauestysstrangesecureclub[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">reauestysstrangesecureereauestyss[.]us<\/td>\n<td width=\"208\">reauestysstrangesecureworld[.]us<\/td>\n<td width=\"208\">receivedsstrangesecureclub[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">receivedsstrangesecuredigital[.]us<\/td>\n<td width=\"208\">receivedsstrangesecureereceivedss[.]us<\/td>\n<td width=\"208\">receivedsstrangesecurelive[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">receivedsstrangesecurenetwork[.]us<\/td>\n<td width=\"208\">receivedsstrangesecuretoday[.]us<\/td>\n<td width=\"208\">receivedsstrangesecurevip[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">receivedsstrangesecureworld[.]us<\/td>\n<td width=\"208\">replysstrangesecurebest[.]us<\/td>\n<td width=\"208\">replysstrangesecureclub[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangesecuredigital[.]us<\/td>\n<td width=\"208\">replysstrangesecureereplyss[.]us<\/td>\n<td width=\"208\">replysstrangesecurenetwork[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangesecuretoday[.]us<\/td>\n<td width=\"208\">replysstrangesecurevip[.]us<\/td>\n<td width=\"208\">replysstrangesecureworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sendsstrangesecurevip[.]us<\/td>\n<td width=\"208\">esendsstrangelife[.]us<\/td>\n<td width=\"208\">esendsstrangenetwork[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">esendsstrangetoday[.]us<\/td>\n<td width=\"208\">esendsstrangeus[.]us<\/td>\n<td width=\"208\">esendsstrangeworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">sendsstrangesecureclub[.]us<\/td>\n<td width=\"208\">sendsstrangesecurelife[.]us<\/td>\n<td width=\"208\">plysstrangelifes[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">intulifeinoi[.]us<\/td>\n<td width=\"208\">replysstrangerocks[.]us<\/td>\n<td width=\"208\">invpaymentnowe[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangelifes[.]us<\/td>\n<td width=\"208\">replysstrangenetwork[.]us<\/td>\n<td width=\"208\">invdeliverynowr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereceivedggstangevip[.]us<\/td>\n<td width=\"208\">ereplyggstangerocks[.]us<\/td>\n<td width=\"208\">servicceivedsstrangeworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">servicplysstrangesecureasia[.]us<\/td>\n<td width=\"208\">servicplysstrangeservicplys[.]us<\/td>\n<td width=\"208\">emailboostgeasia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">emailboostgeereplys[.]us<\/td>\n<td width=\"208\">emailboostgenetwork[.]us<\/td>\n<td width=\"208\">emailboostgerocks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">eontaysstrangedigital[.]us<\/td>\n<td width=\"208\">eontaysstrangeeontays[.]us<\/td>\n<td width=\"208\">eontaysstrangelife[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">eontaysstrangelifes[.]us<\/td>\n<td width=\"208\">epropivedsstrangeworld[.]us<\/td>\n<td width=\"208\">ereceivedggstangeworld[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">ereplyggstangelife[.]us<\/td>\n<td width=\"208\">frostsstrangevip[.]us<\/td>\n<td width=\"208\">servicplysstrangerocks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">invdeliverynow[.]us<\/td>\n<td width=\"208\">invpaymentnowlife[.]us<\/td>\n<td width=\"208\">invdeliverynowes[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">invpaymentnowwork[.]us<\/td>\n<td width=\"208\">replysstrangedigitals[.]us<\/td>\n<td width=\"208\">replysstrangelife[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"208\">replysstrangelifee[.]us<\/td>\n<td width=\"208\">replystrangeracs[.]us<\/td>\n<td width=\"208\"><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3>RandomU domains<\/h3>\n<table>\n<tbody>\n<tr>\n<td width=\"156\">cnewyllansf[.]us<\/td>\n<td width=\"156\">kibintiwl[.]us<\/td>\n<td width=\"156\">planetezs[.]us<\/td>\n<td width=\"156\">sakgeldvi[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">rdoowvaki[.]us<\/td>\n<td width=\"156\">kabelrandjc[.]us<\/td>\n<td width=\"156\">wembaafag[.]us<\/td>\n<td width=\"156\">postigleip[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">jujubugh[.]us<\/td>\n<td width=\"156\">honidefic[.]us<\/td>\n<td width=\"156\">utietang[.]us<\/td>\n<td width=\"156\">scardullowv[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">vorlassebv[.]us<\/td>\n<td width=\"156\">jatexono[.]us<\/td>\n<td width=\"156\">vlevaiph[.]us<\/td>\n<td width=\"156\">bridgetissimema[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">schildernjc[.]us<\/td>\n<td width=\"156\">francadagf[.]us<\/td>\n<td width=\"156\">strgatibp[.]us<\/td>\n<td width=\"156\">jelenskomna[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">prependerac[.]us<\/td>\n<td width=\"156\">oktagonisa[.]us<\/td>\n<td width=\"156\">enjaularszr[.]us<\/td>\n<td width=\"156\">opteahzf[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">skaplyndiej[.]us<\/td>\n<td width=\"156\">dirnaichly[.]us<\/td>\n<td width=\"156\">kiesmanvs[.]us<\/td>\n<td width=\"156\">gooitounl[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">izvoznojai[.]us<\/td>\n<td width=\"156\">kuphindanv[.]us<\/td>\n<td width=\"156\">pluienscz[.]us<\/td>\n<td width=\"156\">huyumajr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">arrutisdo[.]us<\/td>\n<td width=\"156\">loftinumkx[.]us<\/td>\n<td width=\"156\">ffermwyrzf[.]us<\/td>\n<td width=\"156\">hectorfranez[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">munzoneia[.]us<\/td>\n<td width=\"156\">savichicknc[.]us<\/td>\n<td width=\"156\">nadurogak[.]us<\/td>\n<td width=\"156\">raceaddicteg[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mpixiris[.]us<\/td>\n<td width=\"156\">lestenas[.]us<\/td>\n<td width=\"156\">collahahhaged[.]us<\/td>\n<td width=\"156\">enayilebl[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">hotteswc[.]us<\/td>\n<td width=\"156\">kupakiliayw[.]us<\/td>\n<td width=\"156\">deroutarek[.]us<\/td>\n<td width=\"156\">pomagatia[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mizbebzpe[.]us<\/td>\n<td width=\"156\">firebrandig[.]us<\/td>\n<td width=\"156\">univerzamjw[.]us<\/td>\n<td width=\"156\">amigosenrutavt[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">kafrdaaia[.]us<\/td>\n<td width=\"156\">cimadalfj[.]us<\/td>\n<td width=\"156\">ubrzanihaa[.]us<\/td>\n<td width=\"156\">yamashumiks[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">jakartayd[.]us<\/td>\n<td width=\"156\">cobiauql[.]us<\/td>\n<td width=\"156\">idiofontg[.]us<\/td>\n<td width=\"156\">hoargettattzt[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">encilips[.]us<\/td>\n<td width=\"156\">dafanapydutsb[.]us<\/td>\n<td width=\"156\">intereqr[.]us<\/td>\n<td width=\"156\">chestecotry[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">diegdoceqy[.]us<\/td>\n<td width=\"156\">ffwdenaiszh[.]us<\/td>\n<td width=\"156\">sterinaba[.]us<\/td>\n<td width=\"156\">wamwitaoko[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">peishenthe[.]us<\/td>\n<td width=\"156\">hegenheimlr[.]us<\/td>\n<td width=\"156\">educarepn[.]us<\/td>\n<td width=\"156\">ayajuaqo[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">imkingdanuj[.]us<\/td>\n<td width=\"156\">dypeplayentqt[.]us<\/td>\n<td width=\"156\">traktorkaqk[.]us<\/td>\n<td width=\"156\">prilipexr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">collazzird[.]us<\/td>\n<td width=\"156\">sentaosez[.]us<\/td>\n<td width=\"156\">vangnetxh[.]us<\/td>\n<td width=\"156\">valdreska[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mxcujatr[.]us<\/td>\n<td width=\"156\">angelqtbw[.]us<\/td>\n<td width=\"156\">bescromeobsemyb[.]us<\/td>\n<td width=\"156\">hoogametas[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mlitavitiwj[.]us<\/td>\n<td width=\"156\">pasgemaakhc[.]us<\/td>\n<td width=\"156\">facelijaxg[.]us<\/td>\n<td width=\"156\">harukihotarugf[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">pasosaga[.]us<\/td>\n<td width=\"156\">mashimariokt[.]us<\/td>\n<td width=\"156\">vodoclundqs[.]us<\/td>\n<td width=\"156\">trofealnytw[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">cowboyie[.]us<\/td>\n<td width=\"156\">dragovanmm[.]us<\/td>\n<td width=\"156\">jonuzpura[.]us<\/td>\n<td width=\"156\">cahurisms[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">leetzetli[.]us<\/td>\n<td width=\"156\">jonrucunopz[.]us<\/td>\n<td width=\"156\">flaaksik[.]us<\/td>\n<td width=\"156\">wizjadne[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">zatsopanogn[.]us<\/td>\n<td width=\"156\">roblanzq[.]us<\/td>\n<td width=\"156\">barbwirelx[.]us<\/td>\n<td width=\"156\">givolettoan[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">gyfarosmt[.]us<\/td>\n<td width=\"156\">zastirkjx[.]us<\/td>\n<td width=\"156\">sappianoyv[.]us<\/td>\n<td width=\"156\">noneedfordayvnb[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">andreguidiao[.]us<\/td>\n<td width=\"156\">concubinsel[.]us<\/td>\n<td width=\"156\">meljitebj[.]us<\/td>\n<td width=\"156\">alcalizezsc[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">springenmw[.]us<\/td>\n<td width=\"156\">kongovkamev[.]us<\/td>\n<td width=\"156\">starlitent[.]us<\/td>\n<td width=\"156\">cassineraqy[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ariankacf[.]us<\/td>\n<td width=\"156\">plachezxr[.]us<\/td>\n<td width=\"156\">abulpasastq[.]us<\/td>\n<td width=\"156\">scraithehk[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">wintertimero[.]us<\/td>\n<td width=\"156\">abbylukis[.]us<\/td>\n<td width=\"156\">lumcrizal[.]us<\/td>\n<td width=\"156\">trokrilenyr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">skybdragonqx[.]us<\/td>\n<td width=\"156\">pojahuez[.]us<\/td>\n<td width=\"156\">rambalegiec[.]us<\/td>\n<td width=\"156\">relucrarebk[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">vupardoumeip[.]us<\/td>\n<td width=\"156\">punicdxak[.]us<\/td>\n<td width=\"156\">vaninabaranaogw[.]us<\/td>\n<td width=\"156\">yesitsmeagainle[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">upcominge[.]us<\/td>\n<td width=\"156\">arwresaub[.]us<\/td>\n<td width=\"156\">zensimup[.]us<\/td>\n<td width=\"156\">joelstonem[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ciflaratzz[.]us<\/td>\n<td width=\"156\">adespartc[.]us<\/td>\n<td width=\"156\">maaltijdr[.]us<\/td>\n<td width=\"156\">acmindiaj[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mempetebyj[.]us<\/td>\n<td width=\"156\">itorandat[.]us<\/td>\n<td width=\"156\">galenicire[.]us<\/td>\n<td width=\"156\">cheldisalk[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">zooramawpreahkt[.]us<\/td>\n<td width=\"156\">sijamskojoc[.]us<\/td>\n<td width=\"156\">fliefedomrr[.]us<\/td>\n<td width=\"156\">ascenitianyrg[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">tebejavaaq[.]us<\/td>\n<td width=\"156\">finnerssshu[.]us<\/td>\n<td width=\"156\">slimshortyub[.]us<\/td>\n<td width=\"156\">angstigft[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">avedaviya[.]us<\/td>\n<td width=\"156\">aasthakathykh[.]us<\/td>\n<td width=\"156\">nesklonixt[.]us<\/td>\n<td width=\"156\">drywelyza[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">paginomxd[.]us<\/td>\n<td width=\"156\">gathesitehalazw[.]us<\/td>\n<td width=\"156\">antinodele[.]us<\/td>\n<td width=\"156\">ferestat[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">tianaoeuat[.]us<\/td>\n<td width=\"156\">pogilasyg[.]us<\/td>\n<td width=\"156\">mjawxxik[.]us<\/td>\n<td width=\"156\">bertolinnj[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">auswalzenna[.]us<\/td>\n<td width=\"156\">mmmikeyvb[.]us<\/td>\n<td width=\"156\">megafonasgc[.]us<\/td>\n<td width=\"156\">litnanjv[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">boockmasi[.]us<\/td>\n<td width=\"156\">andreillazf[.]us<\/td>\n<td width=\"156\">vampirupn[.]us<\/td>\n<td width=\"156\">lionarivv[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ihmbklkdk[.]us<\/td>\n<td width=\"156\">okergeeliw[.]us<\/td>\n<td width=\"156\">forthabezb[.]us<\/td>\n<td width=\"156\">trocetasss[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">kavamennci[.]us<\/td>\n<td width=\"156\">mipancepezc[.]us<\/td>\n<td width=\"156\">infuuslx[.]us<\/td>\n<td width=\"156\">dvodomnogeg[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">zensingergy[.]us<\/td>\n<td width=\"156\">eixirienhj[.]us<\/td>\n<td width=\"156\">trapunted[.]us<\/td>\n<td width=\"156\">greatfutbolot[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">porajskigx[.]us<\/td>\n<td width=\"156\">mumbleiwa[.]us<\/td>\n<td width=\"156\">cilindrarqe[.]us<\/td>\n<td width=\"156\">uylateidr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">sdsandrahuin[.]us<\/td>\n<td width=\"156\">trapeesr[.]us<\/td>\n<td width=\"156\">trauttbobw[.]us<\/td>\n<td width=\"156\">bostiwro[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">niqiniswen[.]us<\/td>\n<td width=\"156\">ditionith[.]us<\/td>\n<td width=\"156\">folseine[.]us<\/td>\n<td width=\"156\">zamoreki[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">sonornogae[.]us<\/td>\n<td width=\"156\">xlsadlxg[.]us<\/td>\n<td width=\"156\">varerizu[.]us<\/td>\n<td width=\"156\">seekabelv[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">nisabooz[.]us<\/td>\n<td width=\"156\">pohvalamt[.]us<\/td>\n<td width=\"156\">inassyndr[.]us<\/td>\n<td width=\"156\">ivenyand[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">karbonsavz[.]us<\/td>\n<td width=\"156\">svunturc[.]us<\/td>\n<td width=\"156\">babyrosep[.]us<\/td>\n<td width=\"156\">aardigerf[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">fedrelandx[.]us<\/td>\n<td width=\"156\">degaeriah[.]us<\/td>\n<td width=\"156\">detidiel[.]us<\/td>\n<td width=\"156\">acuendoj[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">peludine[.]us<\/td>\n<td width=\"156\">impermatav[.]us<\/td>\n<td width=\"156\">datsailis[.]us<\/td>\n<td width=\"156\">melenceid[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">beshinon[.]us<\/td>\n<td width=\"156\">dinangnc[.]us<\/td>\n<td width=\"156\">fowiniler[.]us<\/td>\n<td width=\"156\">laibstadtws[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">bischerohc[.]us<\/td>\n<td width=\"156\">muctimpubwz[.]us<\/td>\n<td width=\"156\">jusidalikan[.]us<\/td>\n<td width=\"156\">peerbalkw[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">robesikaton[.]us<\/td>\n<td width=\"156\">thabywnderlc[.]us<\/td>\n<td width=\"156\">osoremep[.]us<\/td>\n<td width=\"156\">krlperuoe[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ntarodide[.]us<\/td>\n<td width=\"156\">bideoskin[.]us<\/td>\n<td width=\"156\">senagena[.]us<\/td>\n<td width=\"156\">kelyldori[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">kawtriatthu[.]us<\/td>\n<td width=\"156\">rbreriaf[.]us<\/td>\n<td width=\"156\">enaqwilo[.]us<\/td>\n<td width=\"156\">monesine[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">onwinaka[.]us<\/td>\n<td width=\"156\">yonhydro[.]us<\/td>\n<td width=\"156\">siostailpg[.]us<\/td>\n<td width=\"156\">bannasba[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">milosnicacz[.]us<\/td>\n<td width=\"156\">tunenida[.]us<\/td>\n<td width=\"156\">sargasseu[.]us<\/td>\n<td width=\"156\">malayabc[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">prokszacd[.]us<\/td>\n<td width=\"156\">premarketcl[.]us<\/td>\n<td width=\"156\">zedyahai[.]us<\/td>\n<td width=\"156\">xinarmol[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">minttaid[.]us<\/td>\n<td width=\"156\">pufuletzpb[.]us<\/td>\n<td width=\"156\">nekbrekerdv[.]us<\/td>\n<td width=\"156\">ppugsasiw[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">katarkamgm[.]us<\/td>\n<td width=\"156\">kyraidaci[.]us<\/td>\n<td width=\"156\">falhiblaqv[.]us<\/td>\n<td width=\"156\">lisusant[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mameriar[.]us<\/td>\n<td width=\"156\">quslinie[.]us<\/td>\n<td width=\"156\">nirdorver[.]us<\/td>\n<td width=\"156\">trocairasec[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">pochwikbz[.]us<\/td>\n<td width=\"156\">ingykhat[.]us<\/td>\n<td width=\"156\">okrzynjf[.]us<\/td>\n<td width=\"156\">razsutegayl[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">dimbachzx[.]us<\/td>\n<td width=\"156\">buchingmc[.]us<\/td>\n<td width=\"156\">iessemda[.]us<\/td>\n<td width=\"156\">fatarelliqi[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">efetivumd[.]us<\/td>\n<td width=\"156\">vdevicioik[.]us<\/td>\n<td width=\"156\">klumppwha[.]us<\/td>\n<td width=\"156\">stefiensi[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">donetzbx[.]us<\/td>\n<td width=\"156\">wetafteto[.]us<\/td>\n<td width=\"156\">denementnd[.]us<\/td>\n<td width=\"156\">cyllvysr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">viweewmokmt[.]us<\/td>\n<td width=\"156\">destescutyi[.]us<\/td>\n<td width=\"156\">craulisrt[.]us<\/td>\n<td width=\"156\">maggiebagglesxt[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">yawapasaqi[.]us<\/td>\n<td width=\"156\">spimilatads[.]us<\/td>\n<td width=\"156\">paseadoryy[.]us<\/td>\n<td width=\"156\">apageyantak[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">magicofaloeaj[.]us<\/td>\n<td width=\"156\">prefatoryhe[.]us<\/td>\n<td width=\"156\">statvaiq[.]us<\/td>\n<td width=\"156\">piketuojaqk[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mushipotatobt[.]us<\/td>\n<td width=\"156\">suergonugoy[.]us<\/td>\n<td width=\"156\">gummiskoxt[.]us<\/td>\n<td width=\"156\">torunikc[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">adoleishswn[.]us<\/td>\n<td width=\"156\">rovljanie[.]us<\/td>\n<td width=\"156\">ivicukfa[.]us<\/td>\n<td width=\"156\">vajarelliwe[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">burksuit[.]us<\/td>\n<td width=\"156\">adoraableio[.]us<\/td>\n<td width=\"156\">bassettsz[.]us<\/td>\n<td width=\"156\">chevyguyxq[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">lunamaosa[.]us<\/td>\n<td width=\"156\">telemovelmi[.]us<\/td>\n<td width=\"156\">pimptazticui[.]us<\/td>\n<td width=\"156\">posteryeiq[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">miriamloiso[.]us<\/td>\n<td width=\"156\">salahlekajl[.]us<\/td>\n<td width=\"156\">inveshilifj[.]us<\/td>\n<td width=\"156\">alquicelbi[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">hitagjafirt[.]us<\/td>\n<td width=\"156\">ohatranqm[.]us<\/td>\n<td width=\"156\">scosebexgofxu[.]us<\/td>\n<td width=\"156\">vivalasuzyygb[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">lugleeghp[.]us<\/td>\n<td width=\"156\">alicuppippn[.]us<\/td>\n<td width=\"156\">wedutuanceseefv[.]us<\/td>\n<td width=\"156\">abnodobemmn[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">zajdilxtes[.]us<\/td>\n<td width=\"156\">inhaltsqxw[.]us<\/td>\n<td width=\"156\">rejtacdat[.]us<\/td>\n<td width=\"156\">contunaag[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">pitajucmas[.]us<\/td>\n<td width=\"156\">delopezmc[.]us<\/td>\n<td width=\"156\">donjimafx[.]us<\/td>\n<td width=\"156\">iheartcoxlc[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">rommelcrxgi[.]us<\/td>\n<td width=\"156\">jorguetky[.]us<\/td>\n<td width=\"156\">jadesellvb[.]us<\/td>\n<td width=\"156\">fintercentrosfs[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ralbarix[.]us<\/td>\n<td width=\"156\">kynnirinnty[.]us<\/td>\n<td width=\"156\">bibulbio[.]us<\/td>\n<td width=\"156\">aspazjagh[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">gleboqrat[.]us<\/td>\n<td width=\"156\">tensinory[.]us<\/td>\n<td width=\"156\">usitniterx[.]us<\/td>\n<td width=\"156\">zaretkyui[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">hentugustqy[.]us<\/td>\n<td width=\"156\">surigatoszuk[.]us<\/td>\n<td width=\"156\">nitoeranybr[.]us<\/td>\n<td width=\"156\">spitzkopuo[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">podkarpatruszz[.]us<\/td>\n<td width=\"156\">milfincasqo[.]us<\/td>\n<td width=\"156\">datatsbjew[.]us<\/td>\n<td width=\"156\">changotme[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">losbindebt[.]us<\/td>\n<td width=\"156\">ninjachuckvb[.]us<\/td>\n<td width=\"156\">desfadavacp[.]us<\/td>\n<td width=\"156\">potkazatiun[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">sernakct[.]us<\/td>\n<td width=\"156\">razmersat[.]us<\/td>\n<td width=\"156\">purtinaah[.]us<\/td>\n<td width=\"156\">ampiovfa[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">durstinyskv[.]us<\/td>\n<td width=\"156\">kreukenct[.]us<\/td>\n<td width=\"156\">shinanyavc[.]us<\/td>\n<td width=\"156\">kolaryta[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">yangtsekk[.]us<\/td>\n<td width=\"156\">voyagedeviema[.]us<\/td>\n<td width=\"156\">elblogdelld[.]us<\/td>\n<td width=\"156\">utiligijc[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">peaplesokqo[.]us<\/td>\n<td width=\"156\">jenggoteq[.]us<\/td>\n<td width=\"156\">dogliairler[.]us<\/td>\n<td width=\"156\">kandizifb[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">flunkmasteraz[.]us<\/td>\n<td width=\"156\">clewpossejj[.]us<\/td>\n<td width=\"156\">hymgaledaja[.]us<\/td>\n<td width=\"156\">gmckayar[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">fagordul[.]us<\/td>\n<td width=\"156\">pnendickhs[.]us<\/td>\n<td width=\"156\">arrogede[.]us<\/td>\n<td width=\"156\">stilenii[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">cafelireao[.]us<\/td>\n<td width=\"156\">poishiuuz[.]us<\/td>\n<td width=\"156\">nonfunccoupyo[.]us<\/td>\n<td width=\"156\">madrigalbta[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">tarad[.]us<\/td>\n<td width=\"156\">sarahcp[.]us<\/td>\n<td width=\"156\">wickyjr[.]us<\/td>\n<td width=\"156\">ghadrn[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">sirvond[.]us<\/td>\n<td width=\"156\">qumarta[.]us<\/td>\n<td width=\"156\">verow[.]us<\/td>\n<td width=\"156\">mondeki[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">lirana[.]us<\/td>\n<td width=\"156\">niarvi[.]us<\/td>\n<td width=\"156\">belena[.]us<\/td>\n<td width=\"156\">qucono[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ulianag[.]us<\/td>\n<td width=\"156\">lenut[.]us<\/td>\n<td width=\"156\">shivave[.]us<\/td>\n<td width=\"156\">jendone[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">seddauf[.]us<\/td>\n<td width=\"156\">jarare[.]us<\/td>\n<td width=\"156\">uchar[.]us<\/td>\n<td width=\"156\">ealesa[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">wyoso[.]us<\/td>\n<td width=\"156\">marnde[.]us<\/td>\n<td width=\"156\">thiath[.]us<\/td>\n<td width=\"156\">aulax[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">bobelil[.]us<\/td>\n<td width=\"156\">jestem[.]us<\/td>\n<td width=\"156\">detala[.]us<\/td>\n<td width=\"156\">phieyen[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">annazo[.]us<\/td>\n<td width=\"156\">dilen[.]us<\/td>\n<td width=\"156\">jelan[.]us<\/td>\n<td width=\"156\">ipedana[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">keulsph[.]us<\/td>\n<td width=\"156\">ztereqm[.]us<\/td>\n<td width=\"156\">rinitan[.]us<\/td>\n<td width=\"156\">natab[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">haritol[.]us<\/td>\n<td width=\"156\">ricould[.]us<\/td>\n<td width=\"156\">lldra[.]us<\/td>\n<td width=\"156\">miniacs[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">zahrajr[.]us<\/td>\n<td width=\"156\">cayav[.]us<\/td>\n<td width=\"156\">pheduk[.]us<\/td>\n<td width=\"156\">qugagad[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">dehist[.]us<\/td>\n<td width=\"156\">letama[.]us<\/td>\n<td width=\"156\">mencyat[.]us<\/td>\n<td width=\"156\">vindae[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">uranc[.]us<\/td>\n<td width=\"156\">handil[.]us<\/td>\n<td width=\"156\">galezay[.]us<\/td>\n<td width=\"156\">bamerna[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">yllyn[.]us<\/td>\n<td width=\"156\">ckavl[.]us<\/td>\n<td width=\"156\">ilalie[.]us<\/td>\n<td width=\"156\">daellee[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">cuparoc[.]us<\/td>\n<td width=\"156\">zelone[.]us<\/td>\n<td width=\"156\">burnile[.]us<\/td>\n<td width=\"156\">uloryrt[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">shexo[.]us<\/td>\n<td width=\"156\">phalbe[.]us<\/td>\n<td width=\"156\">hanolen[.]us<\/td>\n<td width=\"156\">lorria[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">beten[.]us<\/td>\n<td width=\"156\">xuserye[.]us<\/td>\n<td width=\"156\">iclelan[.]us<\/td>\n<td width=\"156\">cwokas[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">vesic[.]us<\/td>\n<td width=\"156\">ontolan[.]us<\/td>\n<td width=\"156\">wajdana[.]us<\/td>\n<td width=\"156\">telama[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">missani[.]us<\/td>\n<td width=\"156\">usinaye[.]us<\/td>\n<td width=\"156\">ertanom[.]us<\/td>\n<td width=\"156\">kericex[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">denaga[.]us<\/td>\n<td width=\"156\">tyderq[.]us<\/td>\n<td width=\"156\">seliza[.]us<\/td>\n<td width=\"156\">kinnco[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">qurtey[.]us<\/td>\n<td width=\"156\">arzenitlu[.]us<\/td>\n<td width=\"156\">vellpoildzu[.]us<\/td>\n<td width=\"156\">keityod[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ltangerineldf[.]us<\/td>\n<td width=\"156\">lizergidft[.]us<\/td>\n<td width=\"156\">serrucheah[.]us<\/td>\n<td width=\"156\">lolricelolad[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">expiantaszg[.]us<\/td>\n<td width=\"156\">hljqfyky[.]us<\/td>\n<td width=\"156\">abarrosch[.]us<\/td>\n<td width=\"156\">lepestrinynr[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">elektroduendevq[.]us<\/td>\n<td width=\"156\">waggonbauwh[.]us<\/td>\n<td width=\"156\">chaquetzgg[.]us<\/td>\n<td width=\"156\">revizijiqa[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">ziggyiqta[.]us<\/td>\n<td width=\"156\">rokenounkaf[.]us<\/td>\n<td width=\"156\">lottemanvl[.]us<\/td>\n<td width=\"156\">corsetatsvp[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">extasiatny[.]us<\/td>\n<td width=\"156\">darkinjtat[.]us<\/td>\n<td width=\"156\">pastorsta[.]us<\/td>\n<td width=\"156\">sategnaxf[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">mordiquedp[.]us<\/td>\n<td width=\"156\">mogulanbub[.]us<\/td>\n<td width=\"156\">aleesexx[.]us<\/td>\n<td width=\"156\">strekktumgz[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">kresanike[.]us<\/td>\n<td width=\"156\">oberhirtesn[.]us<\/td>\n<td width=\"156\">wyddiongw[.]us<\/td>\n<td width=\"156\">etherviltjd[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">gdinauq[.]us<\/td>\n<td width=\"156\">tumisolcv[.]us<\/td>\n<td width=\"156\">oardbzta[.]us<\/td>\n<td width=\"156\">zamislimrx[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">tidifkil[.]us<\/td>\n<td width=\"156\">anwirbtda[.]us<\/td>\n<td width=\"156\">breliaattainoqt[.]us<\/td>\n<td width=\"156\">steinzeitps[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">grafoay[.]us<\/td>\n<td width=\"156\">shuramiok[.]us<\/td>\n<td width=\"156\">sanarteau[.]us<\/td>\n<td width=\"156\">jerininomgv[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">kusturirp[.]us<\/td>\n<td width=\"156\">tenisaragonpu[.]us<\/td>\n<td width=\"156\">terquezajf[.]us<\/td>\n<td width=\"156\">remularegf[.]us<\/td>\n<\/tr>\n<tr>\n<td width=\"156\">nobanior[.]us<\/td>\n<td width=\"156\">julijmc[.]us<\/td>\n<td width=\"156\">dekrapp[.]us<\/td>\n<td width=\"156\">odaljenakd[.]us<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p> READ MORE <a href=\"https:\/\/www.microsoft.com\/security\/blog\/2021\/02\/01\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Sweeping research into massive attacker infrastructures, as well as our real-time monitoring of malware campaigns and attacker activity, directly inform Microsoft security solutions, allowing us to build or improve protections that block malware campaigns and other email threats, both current and future, as well as provide enterprises with the tools for investigating and responding to email campaigns in real-time.<br \/>\nThe post What tracking an attacker email infrastructure tells us about persistent cybercriminal operations appeared first on Microsoft Security. READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":39391,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[276],"tags":[9186,347,5048,4059,9187,9070,7221,1141,188,929],"class_list":["post-39390","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-microsoft-secure","tag-attacker-email-infrastructure","tag-cybersecurity","tag-dridex","tag-emotet","tag-makop","tag-microsoft-defender-for-office-365","tag-microsoft-security-intelligence","tag-necurs","tag-phishing","tag-trickbot"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.8 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-02-01T17:00:06+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png\" \/>\n\t<meta property=\"og:image:width\" content=\"993\" \/>\n\t<meta property=\"og:image:height\" content=\"380\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"25 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations\",\"datePublished\":\"2021-02-01T17:00:06+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/\"},\"wordCount\":4965,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png\",\"keywords\":[\"attacker email infrastructure\",\"Cybersecurity\",\"Dridex\",\"emotet\",\"Makop\",\"Microsoft Defender for Office 365\",\"Microsoft security intelligence\",\"Necurs\",\"Phishing\",\"TrickBot\"],\"articleSection\":[\"Microsoft Secure\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/\",\"name\":\"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png\",\"datePublished\":\"2021-02-01T17:00:06+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/02\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png\",\"width\":993,\"height\":380},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"attacker email infrastructure\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/attacker-email-infrastructure\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/","og_locale":"en_US","og_type":"article","og_title":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-02-01T17:00:06+00:00","og_image":[{"width":993,"height":380,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png","type":"image\/png"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"25 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations","datePublished":"2021-02-01T17:00:06+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/"},"wordCount":4965,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png","keywords":["attacker email infrastructure","Cybersecurity","Dridex","emotet","Makop","Microsoft Defender for Office 365","Microsoft security intelligence","Necurs","Phishing","TrickBot"],"articleSection":["Microsoft Secure"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/","url":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/","name":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png","datePublished":"2021-02-01T17:00:06+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/02\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations.png","width":993,"height":380},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/what-tracking-an-attacker-email-infrastructure-tells-us-about-persistent-cybercriminal-operations\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"attacker email infrastructure","item":"https:\/\/www.threatshub.org\/blog\/tag\/attacker-email-infrastructure\/"},{"@type":"ListItem","position":3,"name":"What tracking an attacker email infrastructure tells us about persistent cybercriminal operations"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39390","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=39390"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/39390\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/39391"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=39390"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=39390"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=39390"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}