2017-11-06 - HANCITOR INFECTION WITH ZEUS PANDA BANKER
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2017-11-06-Hancitor-infection-with-Zeus-Panda-Banker.pcap.zip 477.4 kB (477,360 bytes)
- 2017-11-06-Hancitor-infection-with-Zeus-Panda-Banker.pcap (640,743 bytes)
- 2017-11-06-malware-from-Hancitor-infection.zip 218.3 kB (218,271 bytes)
- 2017-11-06-Hancitor-document.doc (181,760 bytes)
- 2017-11-06-Zeus-Panda-Banker.exe (153,600 bytes)
- 2017-11-06-Hancitor-malspam-16-examples.txt.zip 2.5 kB (2,514 bytes)
- 2017-11-06-Hancitor-malspam-16-examples.txt (40,812 bytes)
- 2017-11-06-Hancitor-notes.txt.zip 1.4 kB (1,369 bytes)
- 2017-11-06-Hancitor-notes.txt (2,883 bytes)
IMAGES
Shown above: Screenshot from one of the emails.
Shown above: Following a link from one of the emails.
Shown above: A document downloaded from one of the links.
Shown above: Traffic from an infection filtered in Wireshark.
Shown above: Zeus Panda Banker made persistent on the infected Windows host.
Click here to return to the main page.