
The server connections made with the victims of the various spear phishing campaign. It hosted a html file that looks like a login page to a document on a platform, that victim is used to log in on daily basis. Victim is forwarded to the malicious server via another html file, that pretends to be a document and is delivered to the email of the victim. The typical target is government official, having access to a classified information.