2017-11-07 - NECURS BOTNET MALSPAM PUSHES LOCKY RANSOMWARE (NO QTBOT/QTLOADER)
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2017-11-07-Necurs-Botnet-malspam-pushes-Locky-ransomware.pcap.zip 461.1 kB (461,062 bytes)
- 2017-11-07-Necurs-Botnet-malspam-and-Locky-ransomware-samples.zip 793.2 kB (793,242 bytes)
NOTES:
- Some fellow researchers at Palo Alto Networks wrote a blog analyzing the 1st stage malware from Necurs Botnet-sourced infections and called it "QtBot." I've also seen it called "QtLoader."
- I haven't noticed any QtBot/QtLoader at all this week from Necurs Botnet malspam, but I haven't been looking very hard.
Shown above: Chain of events I saw today for Necurs Botnet malspam.
IMAGES
Click here to return to the main page.