This technical report presents an investigation into the UNC2975 malvertising campaign, detailing the malware distribution methods and the resulting infections of users' computers with the DANABOT or DARKGATE backdoor. The report outlines the efforts of Mandiant’s Managed Defense Threat Hunting Team, which identified 28 indicators of compromise (IoCs), including 19 domains and nine IP addresses. Further analysis by the WhoisXML API research team expanded the list of IoCs to include 239 email-connected domains, 13 additional IP addresses, and 2,772 string-connected domains. The report documents the WHOIS records of the identified domains, revealing their registration details and geographical distribution. It also includes findings from DNS lookups and threat intelligence checks, which identified additional threats associated with the IP addresses. The investigation culminated in the discovery of 3,027 artifacts connected to the campaign, with several classified as malicious. The report emphasizes the importance of thorough investigations in threat detection.