2017-02-06 - HANCITOR INFECTION

NOTICE:

ASSOCIATED FILES:

  • 2017-02-06-Hancitor-infection-traffic.pcap   (9,171,958 bytes)
  • 2017-02-06-Hancitor-malspam-1550-UTC.eml   (1,880 bytes)
  • 2017-02-06-Terdot.A-Zloader-from-Hancitor-malspam.exe   (296,448 bytes)
  • USPS_invoice_reggie.cage.doc   (204,288 bytes)

NOTES:


Shown above:  Flowchart for this infection traffic.

 

EMAIL


Shown above:  Screenshot from one of the emails.

 

EMAIL HEADERS:

 


Shown above:  Word document downloaded from link in the email.

 

TRAFFIC


Shown above:  Traffic from the infection filtered in Wireshark.

 

ASSOCIATED DOMAINS:

 

FILE HASHES

WORD DOCUMENT:

 

TERDOT.A/ZLOADER:

 

Click here to return to the main page.